CVE Database
/

CVE-2021-24649

Back to search

CVE-2021-24649

Published: Nov 21, 2022

Modified: Apr 30, 2025

PUBLISHED

Description

The WP User Frontend WordPress plugin before 3.5.29 uses a user supplied argument called urhidden in its registration form, which contains the role for the account to be created with, encrypted via wpuf_encryption(). This could allow an attacker having access to the AUTH_KEY and AUTH_SALT constant (via an arbitrary file access issue for example, or if the blog is using the default keys) to create an account with any role they want, such as admin

VendorProductVersions

Unknown

WP User Frontend

affected
0 - < 3.5.29

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now