CVE-2026-74017: WordPress User Registration plugin <= 5.2.7 - Broken Access Control vulnerability
Published Sep 17, 2026
·Updated
Unauthenticated Broken Access Control in User Registration <= 5.2.7 versions.
Affected Software
1 affected component
WordPress User Registration plugin<=5.2.7
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress User Registration pluginto a version that resolves this vulnerability.Fixed in 5.2.8
Event History
Sep 17, 2026
CVE Published
via MITRE·01:24 PM
Data Sourced
via MITRE·01:24 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
The vulnerability is unauthenticated, so an attacker does not need a WordPress account or other prior privileges to attempt exploitation. The network attack vector indicates the affected plugin can be targeted remotely.
2
What security impact is identified?
The reported impact is limited confidentiality impact. No integrity or availability impact is identified in the provided severity vector.
3
Which plugin versions are affected?
User Registration plugin versions 5.2.7 and earlier are identified as affected.