Description Forgotten password reset functionality for local accounts can be used to bypass local authentication checks. Remediation References CVE-2021-27654 Related Vulnerabilities WordPress Plugin Analytics-Gtag Restricted File Upload (1.8.1) WebLogic CVE-2022-21353 Vulnerability (CVE-2022-21353) Django URL Redirection to Untrusted Site ('Open Redirect') Vulnerability (CVE-2017-7233) WordPress Plugin AffiliateWP SQL Injection (1.5.6) MySQL CVE-2019-2991 Vulnerability (CVE-2019-2991) Severity High Classification CVE-2021-27654 CWE-640 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Tags Missing Update Known Vulnerabilities