Impact
The vulnerability is an unauthenticated broken access control flaw in the WordPress User Registration plugin versions 5.2.2 and earlier. An attacker who does not have a verified account can exploit this weakness to create arbitrary user accounts or access restricted registration features, potentially leading to unauthorized access to the site or elevated privileges. The flaw is categorized as CWE‑862, which represents an access control failure impacting the confidentiality and integrity of user data.
Affected Systems
The flaw affects users running Themegrill's User Registration plugin for WordPress on version 5.2.2 or older. The affected plugin is commonly used to manage user sign‑ups and profiles. No other plugin versions or WordPress core versions are listed as impacted.
Risk and Exploitability
CVSS score of 6.5 indicates moderate severity. The EPSS score is not available, so the current exploitation probability is unknown. The vulnerability is not listed in CISA's KEV catalog. The likely attack vector is an unauthenticated HTTP request targeting the plugin's registration endpoint, allowing an attacker to induce the creation of accounts or read restricted data. Immediate patching reduces the risk exposure.
OpenCVE Enrichment