Access violation vulnerability in Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC) 2.8.11

The plugin called “Post Form – Registration Form – Profile Form for User Profiles – Frontend Content Forms for User Submissions (UGC)” in WordPress has a security issue that allows users to gain more privileges than intended. This can happen in all versions up to 2.8.11 because the plugin does not limit what users can do when setting the default role on registration forms. This means that someone with contributor-level access or higher can create a registration form with a custom role, which lets them register as an administrator.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.