CVE-2026-75823: WP User Frontend 3.5.29 - 4.3.11 - Unauthenticated Privilege Escalation via Registration Role Encryption
The User Frontend WordPress plugin before 4.3.12 does not prevent tampering with the role assigned by its registration form, allowing unauthenticated users to register with a higher privileged role, such as Editor.
This affects installations running a PHP build where the sodium extension is unavailable, and where a registration page has been configured. The administrator role cannot be obtained this way.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WP User Frontendto a version that resolves this vulnerability.Fixed in 4.3.12
Event History
Frequently Asked Questions
Which installations are exposed to this issue?
Installations using WP User Frontend versions before 4.3.12 are affected only when the PHP sodium extension is unavailable and a registration page has been configured.
What does an attacker need to exploit it?
An attacker does not need to authenticate. They need access to the configured registration form and can tamper with the role assigned during registration.
What level of access can an attacker gain?
An attacker may register with a higher-privileged role, such as Editor. The Administrator role cannot be obtained through this issue.
What should be prioritized for remediation?
Update WP User Frontend to version 4.3.12 or later. Until updating is possible, disabling or restricting the configured registration page removes the exposed registration path.