Description
WordPress Plugin User Registration-Custom Registration Form, Login Form, and User Profile is prone to a privilege escalation vulnerability. Exploiting this issue may allow attackers to bypass the expected capabilities check and perform otherwise restricted actions; other attacks are also possible. WordPress Plugin User Registration-Custom Registration Form, Login Form, and User Profile version 3.1.5 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin version 3.2.0 or latest
References
Related Vulnerabilities
Liferay Portal Server-Side Request Forgery (SSRF) Vulnerability (CVE-2025-43763)
Jetty Sensitive Information in Resource Not Removed Before Reuse Vulnerability (CVE-2026-5795)
WordPress Plugin EELV Newsletter Cross-Site Scripting (3.3.0)
Oracle JRE Improper Access Control Vulnerability (CVE-2025-53057)