Subscriptions
Tracking
Sign in to view the affected projects.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Thu, 29 Jan 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
N-media
N-media simple User Registration Wordpress Wordpress wordpress |
|
| Vendors & Products |
N-media
N-media simple User Registration Wordpress Wordpress wordpress |
Wed, 28 Jan 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 28 Jan 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Simple User Registration plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 6.7 due to insufficient restriction on the 'profile_save_field' function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to modify their user role by supplying the 'wp_capabilities' parameter during a profile update. | |
| Title | Simple User Registration <= 6.7 - Authenticated (Subscriber+) Privilege Escalation via profile_save_field | |
| Weaknesses | CWE-284 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-01-28T14:33:44.325Z
Reserved: 2026-01-10T14:13:05.549Z
Link: CVE-2026-0844
Updated: 2026-01-28T14:33:39.962Z
Status : Awaiting Analysis
Published: 2026-01-28T12:15:52.437
Modified: 2026-01-29T16:31:35.700
Link: CVE-2026-0844
No data.
OpenCVE Enrichment
Updated: 2026-01-29T09:18:23Z