Junglewise Threat Intelligence

CVE-2026-25425: ThemeGrill User Registration broken access control

CVE-2026-25425 · Severity: high · CVSS 7.5 · Published 2026-06-15

Technologies: WPEverest User Registration. Vendors: ThemeGrill, WPEverest.

Executive brief

The User Registration plugin for WordPress, which is used to create custom registration and login forms, contains a security flaw in its access control mechanisms. An unauthenticated attacker can exploit this to perform actions that should be restricted to authorized users. This could lead to service disruptions or unauthorized changes to the site's registration processes.

Technical details

A broken access control vulnerability exists in the ThemeGrill User Registration plugin for WordPress due to missing authorization checks (CWE-862). The flaw allows an unauthenticated remote attacker to execute functions that should be restricted, potentially leading to a denial of service (as indicated by the CVSS availability impact). The vulnerability is present in versions up to 5.1.2 and was addressed in version 5.1.3. Attackers can exploit this over the network without any user interaction or prior authentication.

Affected products

  • ThemeGrill User Registration <= 5.1.2

Timeline

  • 2025-12-28: other: Reported by researcher 0xd4rk5id3
  • 2026-05-28: advisory: Patchstack advisory published
  • 2026-06-15: disclosed: NVD publication date

References

Related threats