Unauthenticated Access Control Flaw in User Registration Plugin by WordPress
CVE-2026-52701

6.5MEDIUM

Key Information:

Vendor

WordPress

Vendor
CVE Published:
26 June 2026

What is CVE-2026-52701?

This vulnerability concerns an unauthenticated broken access control flaw in the User Registration Plugin for WordPress. Versions up to and including 5.2.2 are affected, allowing attackers to exploit this weakness, potentially gaining unauthorized access to sensitive areas of the application without proper authentication. This flaw poses a significant risk, as it could lead to unauthorized user registration and manipulation of user data, thereby compromising the integrity and security of WordPress sites utilizing this plugin. Users are recommended to update to the latest version to mitigate the risk.

Affected Version(s)

User Registration <= 5.2.2

References

CVSS V3.1

Score:
6.5
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

nobody09 | Patchstack Bug Bounty Program
.