Executive brief
The User Registration Stripe plugin for WordPress, which handles paid user registrations via Stripe, contains a security flaw that allows unauthorized individuals to bypass access controls. This could allow an attacker to perform actions or access data they should not have permission to see, potentially impacting user management and registration workflows. Business operations may be affected if unauthorized users can manipulate registration processes or access sensitive customer information.
Technical details
The User Registration Stripe plugin for WordPress (versions up to and including 1.3.14) is vulnerable to broken access control due to missing authorization checks (CWE-862). An unauthenticated remote attacker can exploit this flaw to execute functions or access data that should be restricted to higher-privileged users. The vulnerability is rated with a CVSS 3.1 score of 8.2, indicating high impact on confidentiality and partial impact on integrity. Users are advised to update to version 1.3.15 or later to remediate the issue.
Affected products
- ThemeGrill User Registration Stripe <= 1.3.14
Timeline
- 2025-12-31: other: Reported by researcher 0xd4rk5id3
- 2026-04-16: advisory: Patchstack published advisory
- 2026-06-17: disclosed: CVE published to NVD