What the vulnerability does
01Description
Subscriber Broken Authentication in User Registration <= 5.2.6 versions.
CVSS base score
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L
What the vulnerability does
Subscriber Broken Authentication in User Registration <= 5.2.6 versions.
Explanation of Vulnerability in Simple Terms
User Registration for WordPress contains an authentication bypass vulnerability that allows attackers with low-level access to modify data or disrupt site functionality. The flaw stems from insufficient identity verification in the authentication mechanism. Attackers can spoof credentials to bypass normal login checks. Update to a version newer than 5.2.6 to remediate.
What an attacker can do
Bypass authentication checks and modify site data or cause service disruption.
Potential impact on your site
Authenticated users with low privileges could alter content or disable features without proper authorization.
Conditions required to exploit
Attacker must have low-level user account access to the site.
Key dates
External resources
Related vulnerabilities