CVE-2026-75824
Received Received - Intake

Unauthenticated Account Creation in User Frontend WordPress Plugin

Vulnerability report for CVE-2026-75824, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: WPScan

Description

The User Frontend WordPress plugin before 4.3.12 does not check whether the site allows user registration before creating an account, allowing unauthenticated users to create accounts on sites where registration is disabled. The created account receives the site's default role.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
wp_user_frontend wp_user_frontend From 2.5.8 (inc) to 4.3.11 (inc)
wp_user_frontend wp_user_frontend 4.3.12

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-75824 affects the WP User Frontend WordPress plugin versions 2.5.8 through 4.3.11. It allows unauthenticated users to create accounts on WordPress sites even when user registration is disabled. The plugin does not check if registration is permitted before creating an account, assigning the default role to the new user.

Detection Guidance

Check the installed version of the WP User Frontend plugin. If it is between 2.5.8 and 4.3.11, the system is vulnerable. You can verify this by inspecting the plugin files or using WordPress admin panel to view the plugin version.

Impact Analysis

This vulnerability allows unauthorized users to create accounts on your WordPress site without permission. This could lead to unauthorized access, potential data breaches, or misuse of site resources. Attackers might exploit this to gain control or disrupt site operations.

Compliance Impact

This vulnerability could violate compliance requirements such as GDPR or HIPAA by allowing unauthorized account creation, potentially exposing user data or enabling unauthorized access to sensitive information. It may lead to legal penalties or reputational damage.

Mitigation Strategies

Update the WP User Frontend plugin to version 4.3.12 or later immediately to patch the vulnerability. If updating is not possible, consider disabling the plugin until an update is available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-75824. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart