CVE-2023-52209 HIGH

CVE-2023-52209: WordPress WPForms User Registration plugin <= 2.1.0 - Authenticated Privilege Escalation vulnerability

Vendor Wpforms, Llc.
Product WPForms User Registration
Weakness CWE-269
Published August 1, 2024
Last update April 28, 2026

CVSS base score

8.0/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction Required
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

Improper Privilege Management vulnerability in WPForms, LLC. WPForms User Registration allows Privilege Escalation.This issue affects WPForms User Registration: from n/a through 2.1.0.

Explanation of Vulnerability in Simple Terms

02Summary

WPForms User Registration versions up to 2.1.0 contain a privilege management flaw that allows authenticated users with low privileges to perform actions reserved for higher-privilege roles. An attacker must be logged in and trick a user into clicking a malicious link. This can result in unauthorized data access, modification, or site disruption.

What an attacker can do

03Attacker Capabilities

Read, modify, or delete sensitive data and site settings beyond their assigned role.

Potential impact on your site

04Site Impact

Unauthorized users can escalate their capabilities to perform admin-level actions on registration forms and user data.

Conditions required to exploit

05Prerequisites

Attacker must be logged in as a low-privilege user and the victim must click a link or visit a page.

Key dates

06Disclosure timeline

August 1, 2024 CVE published
April 28, 2026 Record updated

Related vulnerabilities

08Related CVE