Impact
The Choose User Role at Registration WordPress plugin, prior to version 1.3.3, fails to verify that the user‑requested role during registration is among the roles granted permission by an administrator. An unauthenticated visitor can therefore specify the Administrator role in their registration request. Once that request is approved, the visitor is granted administrative privileges, effectively allowing an attacker to elevate privileges without prior authentication.
Affected Systems
All WordPress sites that have installed the Choose User Role at Registration plugin version 1.3.2 or earlier and have enabled the role selection during registration. The vulnerability exists in every installation of this plugin where the role selection interface is active and public registration is permitted; no specific vendor or product name other than the plugin itself is mentioned.
Risk and Exploitability
The CVSS score of 7.5 classifies this as a high‑severity flaw, and the EPSS score of less than 1% indicates that exploitation is currently unlikely in the wild. The risk is elevated because any site that allows public registration can be affected, and once a role has been approved, the attacker receives full administrative rights, impacting confidentiality, integrity, and availability. Based on the description, it is inferred that the attacker must have access to the public registration form, making the attack vector network‑based and unauthenticated.
OpenCVE Enrichment