CVE-2026-75823 PUBLISHED

WP User Frontend 3.5.29 - 4.3.11 - Unauthenticated Privilege Escalation via Registration Role Encryption

Assigner: WPScan
Reserved: 18.08.2026 Published: 30.09.2026 Updated: 30.09.2026

The User Frontend WordPress plugin before 4.3.12 does not prevent tampering with the role assigned by its registration form, allowing unauthenticated users to register with a higher privileged role, such as Editor.

This affects installations running a PHP build where the sodium extension is unavailable, and where a registration page has been configured. The administrator role cannot be obtained this way.

Product Status

Vendor Unknown
Product User Frontend
Versions Default: unaffected
  • affected from 3.5.29 to 4.3.12 (excl.)

Credits

  • Murad Akhmedov finder
  • WPScan coordinator

References

Problem Types

  • CWE-269 Improper Privilege Management CWE