天下漏洞,尽知其名
HIGH

CVE-2026-75823 User Frontend 权限提升漏洞

影响未认证用户可注册为高权限角色,如编辑

AI 研判

WordPress 插件 User Frontend 在 4.3.12 之前的版本中,其注册表单未对提交的角色参数进行有效校验,导致未认证用户可篡改注册角色。该漏洞影响运行在缺少 sodium 扩展的 PHP 环境且已配置注册页面的站点,攻击者可借此获得 Editor 等高权限角色,但无法直接获取管理员角色。

影响范围

User Frontend

User Frontend WordPress 插件 4.3.12 之前的版本;需运行在 sodium 扩展不可用的 PHP 环境,且站点已配置注册页面。

漏洞详情

漏洞类型为权限提升,成因是插件注册表单在处理用户提交数据时未对角色字段做服务端校验,允许客户端篡改。利用方式为未认证攻击者向注册接口提交被篡改的高权限角色值,从而以该角色完成注册。由于 sodium 扩展缺失可能影响相关加密或校验逻辑,进一步降低了利用门槛。

利用条件与风险

利用前提是目标站点启用了该插件的注册页面且 PHP 环境缺少 sodium 扩展;实战中攻击者可获得 Editor 权限,进而可能进一步扩大影响,但无法直接获得管理员权限。

修复建议

官方已在 4.3.12 版本中修复,建议升级至 4.3.12 或更高版本。临时缓解措施包括禁用该插件的公开注册功能,或确保 PHP 环境启用 sodium 扩展。

原始情报

The User Frontend WordPress plugin before 4.3.12 does not prevent tampering with the role assigned by its registration form, allowing unauthenticated users to register with a higher privileged role, such as Editor.

This affects installations running a PHP build where the sodium extension is unavailable, and where a registration page has been configured. The administrator role cannot be obtained this way.