CVE-2026-75824: WP User Frontend 2.5.8 - 4.3.11 - Unauthenticated Account Creation with Registration Disabled
The User Frontend WordPress plugin before 4.3.12 does not check whether the site allows user registration before creating an account, allowing unauthenticated users to create accounts on sites where registration is disabled.
The created account receives the site's default role.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WP User Frontendto a version that resolves this vulnerability.Fixed in 4.3.12
Event History
Frequently Asked Questions
Which deployments are exposed?
Sites using WP User Frontend versions before 4.3.12 are exposed if the plugin can be used to create accounts, even when WordPress registration is disabled. The issue affects accounts created through the plugin's registration functionality.
What access does an attacker need?
An attacker does not need to authenticate. They can create an account remotely, and the account is assigned the site's configured default role.
What should be done if registration is intentionally disabled?
Update WP User Frontend to version 4.3.12 or later. Until the update is applied, review the plugin's account-registration functionality and monitor for unexpected newly created accounts with the site's default role.