vendor:
Frontend Login and Registration Blocks Plugin
by:
Md Shoriful Islam (RootHarpy)
6.1
CVSS
HIGH
Privilege Escalation
269
CWE
Product Name: Frontend Login and Registration Blocks Plugin
Affected Version From: 1.0.7
Affected Version To: 1.0.7
Patch Exists: NO
Related CWE: CVE-2025-3605
CPE: a:wordpress:frontend_login_and_registration_blocks:1.0.7
Platforms Tested: Ubuntu 22.04 + WordPress 6.5.2
2025
WordPress Frontend Login and Registration Blocks Plugin 1.0.7 – Privilege Escalation
The WordPress Frontend Login and Registration Blocks Plugin version 1.0.7 allows attackers to escalate privileges by exploiting a vulnerability in the 'flrblocksusersettingsupdatehandle' action. This can lead to unauthorized changes in user settings.
Mitigation:
Update to a version higher than 1.0.7 to mitigate this privilege escalation vulnerability.