← Voltar à pesquisa de CVEs

CVE-2026-14250

Themehunk

Descrição

The Themehunk Login Registration plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.0.2. This is due to the handle_frontend_register() function in the unauthenticated /thlogin/v1/register REST endpoint accepting a user-controlled -role- parameter and validating it only against get_editable_roles() — which returns every defined editable site role, including -editor- — before passing it to wp_insert_user(). This makes it possible for unauthenticated attackers, when public user registration is enabled, to create new accounts with the editor role.

CVSS 6.3EPSS 0.209%Risco 0.64
Ver fonte
Publicação
2026-07-08 12:17:20
Versões afetadas
<=1.0.2
Tipo
Aplicação web
Vetor
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L