CVE-2026-75824: Unknown User Frontend
Medium severity, CVSS 5.3. EPSS: 0.2% chance of exploitation in the next 30 days.
The User Frontend WordPress plugin before 4.3.12 does not check whether the site allows user registration before creating an account, allowing unauthenticated users to create accounts on sites where registration is disabled. The created account receives the site's default role.
Affected products
- Unknown User Frontend: from 2.5.8, before 4.3.12 (fixed in 4.3.12)
Published 2026-09-30. Last modified 2026-09-30.