Executive brief
User Registration is a WordPress plugin that allows site administrators to create user registration and login forms on their site. A broken access control vulnerability in versions up to 5.2.7 could allow unauthenticated attackers to access pages or perform actions they should not be permitted to, such as viewing other users' data. This could expose sensitive user information and compromise account security.
Technical details
The vulnerability is a broken access control issue in the User Registration WordPress plugin affecting versions up to 5.2.7. An unauthenticated attacker can bypass access restrictions to access pages or perform actions that should be restricted to authorized users. The vulnerability requires no authentication and is accessible over the network via the WordPress site. Exploitation allows attackers to view or manipulate unauthorized data. The vulnerability has been patched in version 5.2.8 and later.
Affected products
- ThemeGrill User Registration <=5.2.7
Timeline
- 2026-09-16: disclosed
- 2026-09-16: patched: Fixed in version 5.2.8