Junglewise Threat Intelligence

CVE-2026-40726: ThemeGrill User Registration Stripe broken access control

CVE-2026-40726 · Severity: high · CVSS 8.2 · Published 2026-06-17

Vendors: ThemeGrill.

Executive brief

The User Registration Stripe plugin for WordPress, which handles paid user registrations via Stripe, contains a security flaw that allows unauthorized individuals to bypass access controls. This could allow an attacker to perform actions or access data they should not have permission to see, potentially impacting user management and registration workflows. Business operations may be affected if unauthorized users can manipulate registration processes or access sensitive customer information.

Technical details

The User Registration Stripe plugin for WordPress (versions up to and including 1.3.14) is vulnerable to broken access control due to missing authorization checks (CWE-862). An unauthenticated remote attacker can exploit this flaw to execute functions or access data that should be restricted to higher-privileged users. The vulnerability is rated with a CVSS 3.1 score of 8.2, indicating high impact on confidentiality and partial impact on integrity. Users are advised to update to version 1.3.15 or later to remediate the issue.

Affected products

  • ThemeGrill User Registration Stripe <= 1.3.14

Timeline

  • 2025-12-31: other: Reported by researcher 0xd4rk5id3
  • 2026-04-16: advisory: Patchstack published advisory
  • 2026-06-17: disclosed: CVE published to NVD

References

Related threats