CVE-2026-42652: WordPress User Registration plugin <= 5.1.5 - Cross Site Scripting (XSS) vulnerability
Published Apr 29, 2026
·Updated
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpeverest User Registration user-registration allows Reflected XSS.This issue affects User Registration: from n/a through <= 5.1.5.
Affected Software
1 affected component
WPEverest User Registration<=5.1.5
Event History
Apr 29, 2026
CVE Published
via MITRE·10:40 AM
Data Sourced
via MITRE·10:40 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·12:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2026-42652?
CVE-2026-42652 is considered a high severity vulnerability due to the risk of Cross Site Scripting (XSS).
2
How do I fix CVE-2026-42652?
To fix CVE-2026-42652, update the wpeverest User Registration plugin to version 5.1.6 or later.
3
What type of vulnerability is CVE-2026-42652?
CVE-2026-42652 is a Cross Site Scripting (XSS) vulnerability that allows for reflected attacks.
4
Which versions of the User Registration plugin are affected by CVE-2026-42652?
CVE-2026-42652 affects wpeverest User Registration plugin versions 5.1.5 and below.
5
Is user data at risk due to CVE-2026-42652?
Yes, user data is at risk due to the potential for attackers to exploit XSS vulnerabilities and execute malicious scripts.