PT-2026-103022 · WordPress · Wp User Frontend
CVSS v3.1
7.4
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
User Frontend WordPress plugin versions prior to 4.3.12
Description
The plugin fails to prevent tampering with the role assigned via its registration form. This allows unauthenticated users to register with a higher privileged role, such as Editor. This issue occurs on installations using a PHP build where the sodium extension (a library for modern cryptography) is unavailable and a registration page has been configured. The administrator role cannot be obtained through this method.
Recommendations
Update the User Frontend WordPress plugin to version 4.3.12 or later.
Exploit
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wp User Frontend