{"id":"CVE-2026-75823","title":"The User Frontend  WordPress plugin before 4.3.12 does not prevent tampering with the role assigned by its registration form, allowing unauthenticated users to register with a higher privileged role, such as Editor.\n\nThis affects install…","summary":"The User Frontend  WordPress plugin before 4.3.12 does not prevent tampering with the role assigned by its registration form, allowing unauthenticated users to register with a higher privileged role, such as Editor.\n\nThis affects install…","severity":"none","cwe":["CWE-269"],"product":"User Frontend","affected":["user_frontend >= 3.5.29 < 4.3.12"],"published":"2026-09-30","updated":"2026-09-30","sourceUpdated":"2026-09-30T06:17:03.783","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-75823","references":[{"url":"https://wpscan.com/vulnerability/4a385690-3471-4604-aa2a-e120bb31ca53/","label":"contact@wpscan.com"}],"tags":["nvd","cve.org"],"ingestedAt":"2026-09-30T06:58:55.549Z","slug":"CVE-2026-75823","body":"## Overview\n\nThe User Frontend  WordPress plugin before 4.3.12 does not prevent tampering with the role assigned by its registration form, allowing unauthenticated users to register with a higher privileged role, such as Editor.\n\nThis affects installations running a PHP build where the sodium extension is unavailable, and where a registration page has been configured. The administrator role cannot be obtained this way.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}