Impact
The Flex Store Users plugin allows any visitor to register a new user account. The signup and seller‑role functions do not enforce role restrictions, so an attacker can choose the administrator role at registration time. This flaw enables an unauthenticated user to create an account with full administrator privileges, compromising the entire WordPress site. The vulnerability is mitigated only by the presence of additional access checks in future plugin releases.
Affected Systems
This flaw affects the CMSSuperHeroes Flex Store Users WordPress plugin versions 1.1.0 and earlier. The vulnerability is present in all releases up to and including 1.1.0; it is resolved in newer versions released after that point.
Risk and Exploitability
The CVSS score of 9.8 signals a critical severity. Although the EPSS score is below 1%, indicating low current exploitation probability, the flaw can be acted upon remotely without any authentication. The vulnerability is not listed in the CISA KEV catalog. An attacker can trigger the issue by accessing the registration endpoint, optionally providing the fs_type parameter if the Flex Store Seller plugin is active, and specifying the administrator role. Once exploited, the attacker gains full control of the WordPress installation.
OpenCVE Enrichment