Executive brief
The User Registration plugin for WordPress, which is used to create custom registration and login forms, contains a security flaw that allows unauthorized users to bypass access controls. An attacker could exploit this to perform actions or access data they should not have permission for, potentially compromising user management functions. This could lead to unauthorized changes to site settings or the exposure of sensitive user information.
Technical details
A broken access control vulnerability exists in the ThemeGrill User Registration plugin for WordPress due to missing authorization checks (CWE-862). The flaw allows an unauthenticated remote attacker to execute functions or access data that should be restricted to higher-privileged users. The vulnerability is present in versions up to and including 5.2.2. Attackers can exploit this over the network without any user interaction. A patch is available in version 5.2.3.
Affected products
- ThemeGrill User Registration <= 5.2.2
Timeline
- 2026-04-14: other: Reported by researcher nobody09
- 2026-06-22: disclosed: Initial disclosure by Patchstack
- 2026-06-26: advisory: NVD publication date