Impact
The WordPress plugin User Registration & Membership fails to enforce the site's open-registration setting when handling form submissions, allowing any visitor to create new accounts even when the administrator has disabled open registration. This provides attackers with an unverified entry point to create credentials and obtain access to the site, potentially leading to privilege escalation if the site grants elevated roles to newly registered users. The weakness is an improper access control failure.
Affected Systems
Any WordPress site running the User Registration & Membership plugin with a version earlier than 5.2.6. Users of earlier releases are susceptible to unauthenticated account creation regardless of the site's registration settings.
Risk and Exploitability
The flaw is exploitable by any internet-accessible visitor submitting the registration form while registration is disabled. The EPSS score is < 1%, indicating a very low but nonzero exploitation probability, and the vulnerability is not listed in CISA KEV. Despite the low exploitation probability, the lack of authentication control elevates risk. Because an attacker can create arbitrary accounts, the potential impact on confidentiality, integrity, and availability is high, especially if higher-privileged user roles are granted by default. The CVSS score is 7.5, indicating a high severity level.
OpenCVE Enrichment