← WordPress Vulnerabilities
WordPress security by component

Simple User Registration

Simple User Registration is a WordPress component with 4 published CVE records in this archive. The latest tracked vulnerability was published Jan 28, 2026; the highest CVE/CNA score is 9.8.

Plugin slug: wp-registration

CVE-2026-0844: Simple User Registration: Privilege escalation or authentication bypass

Simple User Registration is affected by privilege escalation or authentication bypass. Exploitation requires an authenticated WordPress account. A successful request can grant permissions or access that the caller should not possess.

PublishedJan 28, 2026
Safe version guidanceSee mitigation notes
Safe version
Jan 28, 2026 CVE-2026-0844
Simple User Registration: Privilege escalation or authentication bypass
Simple User Registration is affected by privilege escalation or authentication bypass. Exploitation requires an authenticated WordPress account. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE8.8
NVDPending
Oct 22, 2025 CVE-2025-53428
Simple User Registration: Privilege escalation or authentication bypass
Simple User Registration is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE8.8
NVDPending
Jun 26, 2025 CVE-2025-4334
Simple User Registration: Privilege escalation or authentication bypass
Simple User Registration is affected by privilege escalation or authentication bypass. The vulnerable path is reachable without authentication. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE9.8
NVDPending
Dec 06, 2024 CVE-2024-53810
Simple User Registration: A security weakness
Simple User Registration is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE9.1
NVDPending