VYPR

Themehunk Login Registration

by WordPress

CVEs (1)

  • CVE-2026-14250Jul 8, 2026
    risk 0.00cvss epss 0.00

    The Themehunk Login Registration plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.0.2. This is due to the handle_frontend_register() function in the unauthenticated /thlogin/v1/register REST endpoint accepting a user-controlled…