CVE-2026-75824

Published: Set 30, 2026 Last Modified: Set 30, 2026
ExploitDB:
Other exploit source:
Google Dorks:

Description

AI Translation Available

The User Frontend WordPress plugin before 4.3.12 does not check whether the site allows user registration before creating an account, allowing unauthenticated users to create accounts on sites where registration is disabled.

The created account receives the site's default role.

https://wpscan.com/vulnerability/61b04ece-5050-465e-aa11-de2ff79c6e8c/