Impact
The User Registration PRO plugin allows unauthenticated attackers to delete any user, including administrators, because it lacks proper nonce validation in the user_registration_pro_delete_account() function. The flaw is a classic Cross‑Site Request Forgery that can be triggered by sending a forged request to the deletion endpoint.
Affected Systems
WPEverest User Registration PRO – Custom Registration Form, Login Form, and User Profile WordPress Plugin versions 5.1.3 and earlier are affected.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate risk and the EPSS score of less than 1% suggests a low probability of exploitation in the wild. It is not listed in the CISA KEV catalog. The attack likely requires the victim to click a crafted link or submit a forged form to the vulnerable endpoint, which then processes the deletion without verifying the requester’s intent or authenticity.
OpenCVE Enrichment
EUVD