The WP User Frontend plugin for WordPress is vulnerable to a security issue called ‘Privilege Escalation’. This means that anyone with author-level access or higher, could use a registration form to register as an administrator on any page. This vulnerability is present in all versions up to 3.6.5. To fix this issue, the plugin needs to have better controls on the ability to supply a role on the registration form.