Impact
WordPress sites that use the User Registration plugin version 5.2.6 or older are vulnerable to a broken authentication flaw that allows a subscriber to bypass normal login checks. The flaw stems from improper handling of authentication tokens, classified as CWE-290, and would enable an attacker to gain unauthorized access to subscriber accounts or elevate privileges. This could compromise confidential content and user credentials and provide a foothold for further attacks.
Affected Systems
The vulnerability affects the WordPress User Registration plugin developed by WPEverest, specifically versions up to and including 5.2.6. Sites running these plugin versions, regardless of other configuration settings, are susceptible to authentication bypass.
Risk and Exploitability
The CVSS score of 5.4 indicates moderate severity. EPSS data is unavailable, so current exploit probability cannot be quantified, but the absence of a KEV listing suggests no known active exploitation at this time. The likely attack vector is remote, through the publicly accessible registration interface, allowing adversaries to interact with the plugin endpoint. If exploited, attackers could create or log into subscriber accounts without proper credentials.
OpenCVE Enrichment