Impact
The vulnerability allows a visitor to submit a front‑end user registration form that lacks proper role validation. An attacker can specify an elevated role and bypass safeguards that only partially restrict privileged roles. Once a user account is created with high privileges, the attacker can further modify the account to become an administrator, thereby gaining full control over the WordPress site.
Affected Systems
WordPress sites utilizing the Advanced Custom Fields: Extended plugin version 0.9.2.2 through 0.9.2.6 are affected. The vulnerability exists in all revisions of the plugin before 0.9.2.7 where front‑end user forms do not enforce role restrictions.
Risk and Exploitability
The vulnerability carries a high risk of compromise because it does not require any pre‑existing credentials; any unauthenticated visitor can exploit it. The EPSS score is not available, but the fact that the issue can be triggered from the public interface and results in full administrator rights indicates a significant likelihood of exploitation in a motivated environment. The vulnerability is not listed in the CISA KEV catalog, yet the severity, combined with the lack of authentication barriers, warrants urgent attention. The attack vector is inferred to be a publicly accessible user registration form that accepts role parameters without proper filtering.
OpenCVE Enrichment