Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-14250— Themehunk Login Registration <= 1.0.2 - Unauthenticated Privilege Escalation via 'role' Parameter

Quick assessment

Affected
themehunk TH Login Registration
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

WordPress TH Login Registration是WordPress基金会的一款网站登录与注册管理组件。 WordPress TH Login Registration 1.0.2及之前版本存在权限许可和访问控制问题漏洞,该漏洞源于未经身份验证的/thlogin/v1/register REST端点的handle_frontend_register()函数接受用户控制的'role'参数并仅针对get_editable_roles()进行验证,导致权限提升,未授权的攻击者可在公开用户注册启用时

CVSS 6.3 · Medium EPSS 0.37% · P28

Affected Version Matrix 1

VendorProduct Version RangeStatus
themehunk TH Login Registration ≤ 1.0.2 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-14250

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Themehunk Login Registration <= 1.0.2 - Unauthenticated Privilege Escalation via 'role' Parameter
Source: CVE Program / CVE List V5
Vulnerability Description
The Themehunk Login Registration plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.0.2. This is due to the handle_frontend_register() function in the unauthenticated /thlogin/v1/register REST endpoint accepting a user-controlled 'role' parameter and validating it only against get_editable_roles() — which returns every defined editable site role, including 'editor' — before passing it to wp_insert_user(). This makes it possible for unauthenticated attackers, when public user registration is enabled, to create new accounts with the editor role.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Source: CVE Program / CVE List V5
Vulnerability Type
特权管理不恰当
Source: CVE Program / CVE List V5
Vulnerability Title
WordPress TH Login Registration 权限许可和访问控制问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
WordPress TH Login Registration是WordPress基金会的一款网站登录与注册管理组件。 WordPress TH Login Registration 1.0.2及之前版本存在权限许可和访问控制问题漏洞,该漏洞源于未经身份验证的/thlogin/v1/register REST端点的handle_frontend_register()函数接受用户控制的'role'参数并仅针对get_editable_roles()进行验证,导致权限提升,未授权的攻击者可在公开用户注册启用时
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

Vendor Product Affected Versions CPE Subscribe
themehunk TH Login Registration 0 ~ 1.0.2 -

II. Public POCs for CVE-2026-14250

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-14250

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-14250 (2)

Other References for CVE-2026-14250 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-14250

No comments yet


Leave a comment