Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Wed, 08 Apr 2026 18:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Thu, 29 Jan 2026 10:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
N-media
N-media simple User Registration Wordpress Wordpress wordpress |
|
| Vendors & Products |
N-media
N-media simple User Registration Wordpress Wordpress wordpress |
Wed, 28 Jan 2026 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Wed, 28 Jan 2026 11:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The Simple User Registration plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 6.7 due to insufficient restriction on the 'profile_save_field' function. This makes it possible for authenticated attackers, with minimal permissions such as a subscriber, to modify their user role by supplying the 'wp_capabilities' parameter during a profile update. | |
| Title | Simple User Registration <= 6.7 - Authenticated (Subscriber+) Privilege Escalation via profile_save_field | |
| Weaknesses | CWE-284 | |
| References |
|
|
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Wordfence
Published:
Updated: 2026-04-14T15:08:02.908Z
Reserved: 2026-01-10T14:13:05.549Z
Link: CVE-2026-0844
Updated: 2026-01-28T14:33:39.962Z
Status : Deferred
Published: 2026-01-28T12:15:52.437
Modified: 2026-04-15T00:35:42.020
Link: CVE-2026-0844
No data.
OpenCVE Enrichment
Updated: 2026-04-15T18:00:15Z