Unauthenticated Access Control Flaw in User Registration Plugin by WordPress
CVE-2026-52701
6.5MEDIUM
What is CVE-2026-52701?
This vulnerability concerns an unauthenticated broken access control flaw in the User Registration Plugin for WordPress. Versions up to and including 5.2.2 are affected, allowing attackers to exploit this weakness, potentially gaining unauthorized access to sensitive areas of the application without proper authentication. This flaw poses a significant risk, as it could lead to unauthorized user registration and manipulation of user data, thereby compromising the integrity and security of WordPress sites utilizing this plugin. Users are recommended to update to the latest version to mitigate the risk.
Affected Version(s)
User Registration <= 5.2.2