Description
WordPress Plugin Registration Forms-User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction is prone to multiple vulnerabilities, including security bypass and SQL injection vulnerabilities. Exploiting these issues could allow an attacker to perform otherwise restricted actions and subsequently steal session data and possibly access admin areas of your website or to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database. WordPress Plugin Registration Forms-User Registration Forms, Invitation-Based Registrations, Front-end User Profile, Login Form & Content Restriction version 2.0.15 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 2.0.16 or latest
References
Related Vulnerabilities
Plone CMS Cryptographic Issues Vulnerability (CVE-2012-6661)
WordPress Plugin CM Table Of Contents Cross-Site Scripting (1.0.7)
WordPress Plugin WP Silverlight Media Player Cross-Site Scripting (0.8)
WordPress Plugin Car Rental by BestWebSoft Cross-Site Scripting (1.0.4)
Grafana Improper Authorization Vulnerability (CVE-2026-21724)