---
id: CVE-2026-75824
title: >-
  The User Frontend  WordPress plugin before 4.3.12 does not check whether the
  site allows user registration before creating an account, allowing
  unauthenticated users to create accounts on sites where registration is
  disabled.


  The create…
summary: >-
  The User Frontend  WordPress plugin before 4.3.12 does not check whether the
  site allows user registration before creating an account, allowing
  unauthenticated users to create accounts on sites where registration is
  disabled.


  The create…
severity: none
cwe:
  - CWE-284
product: User Frontend
affected:
  - user_frontend >= 2.5.8 < 4.3.12
published: '2026-09-30'
updated: '2026-09-30'
sourceUpdated: '2026-09-30T06:17:04.360'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-75824'
references:
  - url: 'https://wpscan.com/vulnerability/61b04ece-5050-465e-aa11-de2ff79c6e8c/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-09-30T06:58:55.550Z'
---

## Overview

The User Frontend  WordPress plugin before 4.3.12 does not check whether the site allows user registration before creating an account, allowing unauthenticated users to create accounts on sites where registration is disabled.

The created account receives the site's default role.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
