Impact
The WordPress User Registration Plugin up to version 5.2.7 suffers from a broken access control flaw that allows users to bypass authorization checks and access features intended for authenticated or privileged users. Because authentication is not enforced for certain endpoints, attackers could leverage the plugin’s web interface to attempt unauthorized actions that fall under higher privilege levels, potentially leading to privilege escalation. The CVE description confirms the flaw exists in all releases of the plugin prior to 5.2.8, but does not specify which privileged actions are affected.
Affected Systems
This vulnerability impacts the wpEverest User Registration plugin when running version 5.2.7 or earlier. WordPress sites that have installed the plugin with these versions are vulnerable until the plugin is updated beyond 5.2.8.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the EPSS score is not available. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw remotely via the plugin’s public web interface, requiring no prior authentication. Because the flaw is a broken access control, the potential for privilege escalation exists, but the lack of available exploitation data limits the certainty of real-world exploitation likelihood.
OpenCVE Enrichment