Junglewise Threat Intelligence

CVE-2026-14250: Themehunk Login Registration privilege escalation in REST API

CVE-2026-14250 · Severity: medium · CVSS 6.3 · Published 2026-07-08

Vendors: ThemeHunk.

Executive brief

The Themehunk Login Registration plugin for WordPress, which manages user sign-ups and logins, contains a security flaw that allows unauthorized users to grant themselves elevated permissions. By exploiting this during the registration process, an attacker can create a new account with 'Editor' privileges instead of a standard 'Subscriber' role. This could allow an attacker to modify website content, delete pages, or access sensitive internal data.

Technical details

The vulnerability exists in the handle_frontend_register() function within the /thlogin/v1/register REST endpoint. The root cause is improper validation of the 'role' parameter; the plugin checks the requested role against get_editable_roles() but fails to restrict it to a safe default. Because 'editor' is considered an editable role in many WordPress configurations, an unauthenticated attacker can supply this role during registration when public registration is enabled. This allows for the creation of high-privilege accounts via a single network request. A patch appears to be available in versions following 1.0.2.

Affected products

  • Themehunk TH Login Registration up to, and including, 1.0.2

Timeline

  • 2026-07-08: disclosed
  • 2026-07-08: advisory

References