CyberRota Analysis
AI-GeneratedThe User Frontend WordPress plugin prior to version 4.3.12 is vulnerable to role tampering, enabling unauthenticated users to register with elevated privileges, such as Editor, if the sodium extension is not available in the PHP build. This vulnerability poses a significant risk to sites that allow user registrations through the plugin, potentially leading to unauthorized access and privilege escalation. WordPress administrators should prioritize updating to the latest version to mitigate this risk.
Original NVD Description
The User Frontend WordPress plugin before 4.3.12 does not prevent tampering with the role assigned by its registration form, allowing unauthenticated users to register with a higher privileged role, such as Editor. This affects installations running a PHP build where the sodium extension is unavailable, and where a registration page has been configured. The administrator role cannot be obtained this way.