OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-75823

HIGH · CVSS 7.4 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

The User Frontend WordPress plugin prior to version 4.3.12 is vulnerable to role tampering, enabling unauthenticated users to register with elevated privileges, such as Editor, if the sodium extension is not available in the PHP build. This vulnerability poses a significant risk to sites that allow user registrations through the plugin, potentially leading to unauthorized access and privilege escalation. WordPress administrators should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-75823
Severity
HIGH
CVSS
7.4
EPSS
0.25%
WordPress

Original NVD Description

The User Frontend WordPress plugin before 4.3.12 does not prevent tampering with the role assigned by its registration form, allowing unauthenticated users to register with a higher privileged role, such as Editor. This affects installations running a PHP build where the sodium extension is unavailable, and where a registration page has been configured. The administrator role cannot be obtained this way.