Impact
An unauthenticated broken access control flaw exists in WordPress User Registration plugin versions up to 5.2.6. The vulnerability permits an attacker without valid credentials to exercise privileged operations normally protected for registered users. While the exact scope of the privileged actions is not detailed in the official description, it is inferred that the attacker could access restricted functionality such as user management or sensitive configuration. This weakness is classified as CWE-862, indicating a missing authorization check.
Affected Systems
The affected product is the WordPress User Registration plugin developed by wpeverest. All releases 5.2.6 or earlier are impacted. Versions newer than 5.2.6 are presumed to be free of this flaw, as no additional affected versions are listed.
Risk and Exploitability
The CVSS score of 5.3 places the vulnerability in the medium severity tier. EPSS data is unavailable, so the likelihood of exploitation is not quantified. The vulnerability is not present in the CISA KEV catalog, suggesting no documented widespread exploitation. Based on the description that the flaw allows unauthenticated access, it is inferred that the attack vector involves sending crafted HTTP requests to the plugin’s endpoints through the web interface. No additional exploitation prerequisites are specified, implying the attack could be launched from any publicly accessible WordPress site hosting the vulnerable plugin.
OpenCVE Enrichment