WordPress Plugin Vulnerabilities

WP User Frontend 3.5.29 - 4.3.11 - Unauthenticated Privilege Escalation via Registration Role Encryption

Description

The plugin does not prevent tampering with the role assigned by its registration form, allowing unauthenticated users to register with a higher privileged role, such as Editor.

This affects installations running a PHP build where the sodium extension is unavailable, and where a registration page has been configured. The administrator role cannot be obtained this way.

Proof of Concept

Affects Plugins

Fixed in 4.3.12

References

Classification

Miscellaneous

Original Researcher
Murad Akhmedov
Submitter
Murad Akhmedov
Verified
Yes

Timeline

Publicly Published
2026-09-28 (about 2 days ago)
Added
2026-09-28 (about 1 day ago)
Last Updated
2026-09-29 (about 9 hours ago)

Other