PT-2026-94160 · WordPress · Choose User Role At Registration
CVSS v3.1
7.5
High
| Vector | AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Choose User Role at Registration WordPress plugin versions prior to 1.3.3
Description
An issue exists where the plugin fails to validate the role requested during registration against the roles predefined by an administrator. This allows unauthenticated users to request any role, including the administrator role, which is then granted upon approval of the request. This issue can be exploited if both the role selection feature and public account registration are enabled.
Recommendations
Update to version 1.3.3 or later.
As a temporary mitigation, disable the role selection feature or public account registration.
Exploit
Fix
LPE
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Choose User Role At Registration