Blog

"Prevention is cheaper than a breach"

Live Vulnerability Intelligence

Threat Database

Search CVEs, inspect descriptions, and open detail pages with AI-assisted technical context.

Total2
Critical1
High1
Medium0
Reset
Showing 1-2 of 2 records
Threat Entry Updated 2026-04-15

CVE-2026-0844 - Wp Registration Plugin

The Simple User Registration plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 6.7 due to insufficient restriction on the 'profile_save_field' function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to modify their user role by supplying the 'wp_capabilities' parameter during a profile update.

PLUGIN Wp Registration

CVE-2026-0844

HIGH CVSS 8.8 2026-01-28
Threat Entry Updated 2025-07-09

CVE-2025-4334 - Wp Registration Plugin

The Simple User Registration plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3. This is due to insufficient restrictions on user meta values that can be supplied during registration. This makes it possible for unauthenticated attackers to register as an administrator.

PLUGIN Wp Registration

CVE-2025-4334

CRITICAL CVSS 9.8 2025-06-26
Scroll to top