Access violation vulnerability in WP User Frontend – Registration, User Profile, Membership, Content Restriction, User Directory, and Frontend Post Submission Plugin 3.6.5

The WP User Frontend plugin for WordPress is vulnerable to a security issue called ‘Privilege Escalation’. This means that anyone with author-level access or higher, could use a registration form to register as an administrator on any page. This vulnerability is present in all versions up to 3.6.5. To fix this issue, the plugin needs to have better controls on the ability to supply a role on the registration form.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.