{"error":0,"message":null,"data":{"name":"User Registration &amp; Membership &#8211; Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder","plugin":"user-registration","link":"https:\/\/wordpress.org\/plugins\/user-registration\/","latest":"1789040580","closed":0,"closed_reason":null,"closed_date":null,"vulnerability":[{"uuid":"c66dab82bb57307d821051295bf5e4001d6bda5cfa05355189453fcbaa362b09","name":"User Registration &amp; Membership &#8211; Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder [user-registration] < 2.0.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.0.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2021-24654","name":"CVE-2021-24654","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2021-24654","description":"[en] The User Registration WordPress plugin before 2.0.2 does not properly sanitise the user_registration_profile_pic_url value when submitted directly via the user_registration_update_profile_details AJAX action. This could allow any authenticated user, such as subscriber, to perform Stored Cross-Site attacks when their profile is viewed","date":"2021-10-04"},{"id":"b48bac51aa8c23e06ceb641eae9638a9800293e4","name":"WordPress User Registration plugin <= 2.0.1 - Stored Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/user-registration\/vulnerability\/wordpress-user-registration-plugin-2-0-1-stored-cross-site-scripting-xss-vulnerability","description":"Stored Cross-Site Scripting (XSS) vulnerability discovered by AyeCode Ltd in WordPress User Registration plugin (versions <= 2.0.1).","date":"2021-09-06"},{"id":"5c7a9473-d32e-47d6-9f8e-15b96fe758f2","name":"User Registration &lt; 2.0.2 - Low Privilege Stored Cross-Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/5c7a9473-d32e-47d6-9f8e-15b96fe758f2","description":"The plugin does not properly sanitise the user_registration_profile_pic_url value when submitted directly via the user_registration_update_profile_details AJAX action. This could allow any authenticated user, such as subscriber, to perform Stored Cross-Site attacks when their profile is viewed","date":null},{"id":"6ed19c557a87465e2a497fb934c340cc59b52379","name":"User Registration < 2.0.2 - Authenticated Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/wp-user-manager\/user-registration-202-authenticated-stored-cross-site-scripting","description":"The User Registration WordPress plugin before 2.0.2 does not properly sanitise the user_registration_profile_pic_url value when submitted directly via the user_registration_update_profile_details AJAX action. This could allow any authenticated user, such as subscriber, to perform Stored Cross-Site attacks when their profile is viewed","date":"2021-09-06"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"5.4","severity":"m","exploitable":"2.3","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.3","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}]}},{"uuid":"93d5648230c75d235053b3dc082a0d2a3cf7ee295c09b4b8b2a6e5961397c0c2","name":"User Registration &amp; Membership &#8211; Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder [user-registration] < 1.5.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.5.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"232c18f87d96cd3e176c09bfaa54872a17de8f8f","name":"WordPress User Registration plugin <= 1.5.5 - Authenticated Cross-Site Scripting (XSS) vulnerability","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/user-registration\/vulnerability\/wordpress-user-registration-plugin-1-5-5-authenticated-cross-site-scripting-xss-vulnerability","description":"Authenticated Cross-Site Scripting (XSS) vulnerability found by \"Mr Winst0n\" in WordPress User Registration plugin (versions <= 1.5.5).","date":"2019-01-14"}],"impact":[]},{"uuid":"e942180df46d3bd216edd58b630185c75b1425d144a65b4ae622374016312574","name":"User Registration &amp; Membership &#8211; Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder [user-registration] < 1.5.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.5.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"adfa8b40-25d9-4311-92e8-ff09ed778927","name":"User Registration &lt;= 1.5.5 - Authenticated Cross-Site Scripting (XSS)","link":"https:\/\/wpscan.com\/vulnerability\/adfa8b40-25d9-4311-92e8-ff09ed778927","description":"The User Registration &ndash; Custom Registration Form, Login And User Profile For WordPress WordPress plugin was affected by an Authenticated Cross-Site Scripting (XSS) security vulnerability.","date":null}],"impact":[]},{"uuid":"ccf4e53afe8425b28731dc4e3cc9cc10c439e7af8e8ed913682e66cac56c1e2d","name":"User Registration &amp; Membership &#8211; Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder [user-registration] < 2.2.4.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.2.4.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2022-3912","name":"CVE-2022-3912","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2022-3912","description":"[en] The User Registration WordPress plugin before 2.2.4.1 does not properly restrict the files to be uploaded via an AJAX action available to both unauthenticated and authenticated users, which could allow unauthenticated users to upload PHP files for example.","date":"2022-12-12"},{"id":"578356e2a8618d8baa32fe0fcb008ab8638905bb","name":"User Registration <= 2.2.4  - Authenticated (Subscriber+) Arbitrary File Upload","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/user-registration\/user-registration-224-authenticated-subscriber-arbitrary-file-upload","description":"The User Registration plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the profile_pic_upload function in versions up to, and including, 2.2.4. This makes it possible for authenticated attackers, with subscriber access or higher, to upload arbitrary files on the affected sites server which may make remote code execution possible.","date":"2022-11-21"},{"id":"968c677c-1beb-459b-8fd1-7f70bcaa4f74","name":"User Registration &lt; 2.2.4.1 - Subscriber+ Arbitrary File Upload","link":"https:\/\/wpscan.com\/vulnerability\/968c677c-1beb-459b-8fd1-7f70bcaa4f74","description":"The plugin does not properly restrict the files to be uploaded via an AJAX action available to both unauthenticated and authenticated users, which could allow unauthenticated users to upload PHP files for example.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:H\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"n","i":"h","a":"n","score":"7.5","severity":"h","exploitable":"3.9","impact":"3.6"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:H\/A:N","score":"7.5","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"none","i":"high","a":"none","exploitable":"3.9","impact":"3.6"},"cwe":[{"cwe":"CWE-434","name":"Unrestricted Upload of File with Dangerous Type","description":"The product allows the upload or transfer of dangerous file types that are automatically processed within its environment."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"4fc9b949840ab9c4dedcf02954f3148c47356915c0b8215c61823d0c5b9afac4","name":"User Registration &amp; Membership &#8211; Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder [user-registration] < 1.5.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"1.5.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"a3e39175d7e739be900c3f20b1e1c714c718873a","name":"User Registration <= 1.5.5 - Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/user-registration\/user-registration-155-cross-site-scripting","description":"The User Registration plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.5.5 due to insufficient input sanitization and output escaping via the 'edit-registration' parameter. This makes it possible for authenticated attackers to inject arbitrary web scripts that execute in a victim's browser.","date":"2019-01-09"}],"impact":[]},{"uuid":"cff2dec7ce11efe6979a029c70c9d094f60b5e0e20b9a2e707e8f2cd676b0417","name":"User Registration &amp; Membership &#8211; Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder [user-registration] < 2.3.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.3.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-23987","name":"CVE-2023-23987","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-23987","description":"[en] Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPEverest User Registration plugin <=\u00a02.3.0 versions.","date":"2023-04-06"},{"id":"2e3493a9d33c1f543a32a5220ac405c39e76ee14","name":"WordPress  User Registration Plugin  <= 2.3.0 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/user-registration\/vulnerability\/wordpress-user-registration-custom-registration-form-login-form-and-user-profile-for-wordpress-plugin-2-3-0-cross-site-scripting-xss","description":"Update the WordPress User Registration plugin to the latest available version (at least 2.3.1).\nRio Darmawan discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress User Registration Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 2.3.1.","date":"2023-01-20"},{"id":"5e00de836beedcef637ca79baf7bf50e8d428bc7","name":"User Registration <= 2.3.0  - Authenticated (Administrator+) Stored Cross Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/user-registration\/user-registration-230-authenticated-administrator-stored-cross-site-scripting","description":"The User Registration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via field settings in versions up to, and including, 2.3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrative-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.","date":"2023-01-20"},{"id":"4772f471-15f1-4852-b449-b1b2b2d03770","name":"User Registration &lt; 2.3.1 - Admin+ Stored XSS","link":"https:\/\/wpscan.com\/vulnerability\/4772f471-15f1-4852-b449-b1b2b2d03770","description":"The plugin does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"h","ui":"r","s":"c","c":"l","i":"l","a":"l","score":"5.9","severity":"m","exploitable":"1.7","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:L","score":"5.9","severity":"medium","av":"network","ac":"low","pr":"high","ui":"required","s":"changed","c":"low","i":"low","a":"low","exploitable":"1.7","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"6f0a67167451d34b2d64e536d7272d32eb3d07d1b30e88038272d2f52244252d","name":"User Registration &amp; Membership &#8211; Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder [user-registration] < 2.3.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.3.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-27459","name":"CVE-2023-27459","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-27459","description":"[en] Deserialization of Untrusted Data vulnerability in WPEverest User Registration.This issue affects User Registration: from n\/a through 2.3.2.1.","date":"2024-03-26"},{"id":"d579aeb61b2852b87341225f9c2ee94087a2c9dd","name":"WordPress  User Registration Plugin  <= 2.3.2.1 is vulnerable to PHP Object Injection","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/user-registration\/vulnerability\/wordpress-user-registration-plugin-2-3-2-1-authenticated-php-object-injection-vulnerability","description":"Update the WordPress User Registration plugin to the latest available version (at least 2.3.3).\nRafie Muhammad (Patchstack) discovered and reported this PHP Object Injection vulnerability in WordPress User Registration Plugin. This could allow a malicious actor to execute code injection, SQL injection, path traversal, denial of service, and more if a proper POP chain is present. This vulnerability has been fixed in version 2.3.3.","date":"2023-03-21"},{"id":"eb59b953110698e7aa6e5233caf87d11ff5089bc","name":"User Registration <= 2.3.2.1 - PHP Object Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/user-registration\/user-registration-2321-php-object-injection","description":"The User Registration plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.3.2.1  via deserialization of untrusted input in the following functions: ur_get_user_extra_fields, user_registration_form_field. This allows subscriber-level attackers to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.","date":"2023-03-21"},{"id":"74957215-aba8-4d3a-9418-00bb2c65632f","name":"User Registration &lt; 2.3.3 - Subscriber+ PHP Object Injection","link":"https:\/\/wpscan.com\/vulnerability\/74957215-aba8-4d3a-9418-00bb2c65632f","description":"The plugin unserializes user input via the ur_get_user_extra_fields and user_registration_form_field function, which could allow any authenticated users, such as subscriber to perform PHP Object Injection when a suitable gadget is present on the blog","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"l","score":"7.4","severity":"h","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:L","score":"7.4","severity":"high","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"low","i":"low","a":"low","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-502","name":"Deserialization of Untrusted Data","description":"The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"0389d541c410efc9771b935af0c7795fb7ecbfafd95ac7aab80b1a0f00326b09","name":"User Registration &amp; Membership &#8211; Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder [user-registration] < 2.3.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"2.3.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-29429","name":"CVE-2023-29429","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-29429","description":"[en] Missing Authorization vulnerability in WPEverest User Registration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects User Registration: from n\/a through 2.3.2.1.","date":"2024-12-09"},{"id":"039ca8125c344a1ddf752b1f96733f4a7f168446","name":"WordPress  User Registration Plugin  <= 2.3.2.1 is vulnerable to Broken Access Control","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/user-registration\/vulnerability\/wordpress-user-registration-plugin-2-3-2-1-broken-access-control-vulnerability","description":"Update the WordPress User Registration plugin to the latest available version (at least 2.3.3).\nRafshanzani Suhada discovered and reported this Broken Access Control vulnerability in WordPress User Registration Plugin.  This vulnerability has been fixed in version 2.3.3.","date":"2023-04-06"},{"id":"4415fb17639c156bff6e268ce8de4006a3e9621b","name":"User Registration <= 2.3.2.1 - Missing Authorization via send_test_email","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/user-registration\/user-registration-2321-missing-authorization-via-send-test-email","description":"The User Registration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the send_test_email function in versions up to, and including, 2.3.2.1. This makes it possible for unauthenticated attackers to send a test email.","date":"2023-04-06"},{"id":"EUVD-2023-32998","name":"EUVD-2023-32998","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2023-32998","description":"Missing Authorization vulnerability in WPEverest User Registration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects User Registration: from n\/a through 2.3.2.1.","date":"2024-12-09"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"5.3","severity":"m","exploitable":"3.9","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"3.9","impact":"1.4"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null},"epss":"0.001"}},{"uuid":"077ac6faa316dfc80ad1f47822ac2f53063368cdda0b95e56e3a9583bb43dcee","name":"User Registration &amp; Membership &#8211; Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder [user-registration] < 3.0.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.0.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-3343","name":"CVE-2023-3343","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-3343","description":"[en] The User Registration plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.0.1 via deserialization of untrusted input from the 'profile-pic-url' parameter. This allows authenticated attackers, with subscriber-level permissions and above, to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.","date":"2023-07-13"},{"id":"f5bd68e6e5599cc3f2e138fc2eba91ecce9643af","name":"User Registration <= 3.0.1 - Authenticated (Subscriber+) PHP Object Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/user-registration\/user-registration-301-authenticated-subscriber-php-object-injection","description":"The User Registration plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.0.1 via deserialization of untrusted input from the 'profile-pic-url' parameter. This allows authenticated attackers, with subscriber-level permissions and above, to inject a PHP Object. No POP chain is present in the vulnerable plugin. If a POP chain is present via an additional plugin or theme installed on the target system, it could allow the attacker to delete arbitrary files, retrieve sensitive data, or execute code.","date":"2023-06-29"},{"id":"04c3d8c7-a945-4393-8835-74e489c5dc2d","name":"User Registration &lt; 3.0.2 - Subscriber+ PHP Object Injection","link":"https:\/\/wpscan.com\/vulnerability\/04c3d8c7-a945-4393-8835-74e489c5dc2d","description":"The plugin does not properly sanitize the &#039;profile-pic-url&#039; parameter, leading to a potential PHP Object Injection. This vulnerability stems from the deserialization of untrusted input, potentially enabling a malicious user with subscriber-level permissions to inject a PHP Object. The issue may escalate if a Property Oriented Programming (POP) chain is present via an additional plugin or theme.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"8.8","severity":"h","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"8.8","severity":"high","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-502","name":"Deserialization of Untrusted Data","description":"The product deserializes untrusted data without sufficiently ensuring that the resulting data will be valid."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"d9d80b206b01ed780f4db72f727d3b00c7aca3eaa4e1a831032da4e880c4d055","name":"User Registration &amp; Membership &#8211; Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder [user-registration] < 3.0.2.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.0.2.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-3342","name":"CVE-2023-3342","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-3342","description":"[en] The User Registration plugin for WordPress is vulnerable to arbitrary file uploads due to a hardcoded encryption key and missing file type validation on the 'ur_upload_profile_pic' function in versions up to, and including, 3.0.2. This makes it possible for authenticated attackers with subscriber-level capabilities or above to upload arbitrary files on the affected site's server which may make remote code execution possible. This was partially patched in version 3.0.2 and fully patched in version 3.0.2.1.","date":"2023-07-13"},{"id":"74fe070b1ea5c0c0f43f35774ea9ed80b3f9054a","name":"User Registration <= 3.0.2 - Authenticated (Subscriber+) Arbitrary File Upload","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/user-registration\/user-registration-302-authenticated-subscriber-arbitrary-file-upload","description":"The User Registration plugin for WordPress is vulnerable to arbitrary file uploads due to a hardcoded encryption key and missing file type validation on the 'ur_upload_profile_pic' function in versions up to, and including, 3.0.2. This makes it possible for authenticated attackers with subscriber-level capabilities or above to upload arbitrary files on the affected site's server which may make remote code execution possible. This was partially patched in version 3.0.2 and fully patched in version 3.0.2.1.","date":"2023-07-04"},{"id":"5a66152c35c589f6350d9a3f4c088d8497b2c8fe","name":"WordPress  User Registration Plugin  <= 3.0.2 is vulnerable to Arbitrary File Upload","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/user-registration\/vulnerability\/wordpress-user-registration-plugin-3-0-2-authenticated-arbitrary-file-upload-vulnerability","description":"Update the WordPress User Registration plugin to the latest available version (at least 3.0.2.1).\nLana Codes discovered and reported this Arbitrary File Upload vulnerability in WordPress User Registration Plugin. This could allow a malicious actor to upload any type of file to your website. This can include backdoors which are then executed to gain further access to your website. This vulnerability has been fixed in version 3.0.2.1.","date":"2023-07-04"},{"id":"74c48535-acd2-49e6-9fd2-99754aa6fda0","name":"User Registration &lt; 3.0.2.1 - Subscriber+ Arbitrary File Upload","link":"https:\/\/wpscan.com\/vulnerability\/74c48535-acd2-49e6-9fd2-99754aa6fda0","description":"The plugin uses a static encryption key and does not validate the file path when renaming profile pictures, which could allow any authenticated users, such as subscriber, to upload arbitrary files such as PHP on the server","date":null},{"id":"73d2c831-251e-4883-97ec-16a226f431d7","name":"User Registration &lt; 3.0.2.1 - Subscriber+ Arbitrary File Upload Leading to RCE","link":"https:\/\/wpscan.com\/vulnerability\/73d2c831-251e-4883-97ec-16a226f431d7","description":"The plugin does not validate the file types, and uses a hardcoded encryption key during the profile picture upload process. Authenticated users with minimal permissions, such as a subscriber, can thus upload arbitrary files, potentially leading to remote code execution.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"h","i":"h","a":"h","score":"9.9","severity":"c","exploitable":"3.1","impact":"6.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:H\/I:H\/A:H","score":"9.9","severity":"critical","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"high","i":"high","a":"high","exploitable":"3.1","impact":"6.0"},"cwe":[{"cwe":"CWE-434","name":"Unrestricted Upload of File with Dangerous Type","description":"The product allows the upload or transfer of dangerous file types that are automatically processed within its environment."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"3f7e898249bdc52f7777d4b101044ebc7bdf82c20e360443e1be58fcd551fa23","name":"User Registration &amp; Membership &#8211; Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder [user-registration] < 3.0.4.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.0.4.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2023-5228","name":"CVE-2023-5228","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2023-5228","description":"[en] The User Registration WordPress plugin before 3.0.4.2 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).","date":"2023-11-06"},{"id":"401fe17d8be2d827727309be4622dfeb6be108b8","name":"User Registration \u2013 Custom Registration Form, Login Form And User Profile For WordPress <= 3.0.4.1 - Authenticated (Admin+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/user-registration\/user-registration-custom-registration-form-login-form-and-user-profile-for-wordpress-3041-authenticated-admin-stored-cross-site-scripting","description":"The User Registration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.0.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only affects multi-site installations and installations where unfiltered_html has been disabled.","date":"2023-10-16"},{"id":"1ffe81cca01d09feff99ecc75ec05a837b2f5a4d","name":"WordPress  User Registration Plugin  < 3.0.4.2 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/user-registration\/vulnerability\/wordpress-user-registration-plugin-3-0-4-2-admin-stored-xss-vulnerability","description":"Update the WordPress User Registration plugin to the latest available version (at least 3.0.4.2).\nMohamed Azarudheen discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress User Registration Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 3.0.4.2.","date":"2023-11-07"},{"id":"50ae7008-46f0-4f89-ae98-65dcabe4ef09","name":"User Registration &lt; 3.0.4.2 - Admin+ Stored XSS","link":"https:\/\/wpscan.com\/vulnerability\/50ae7008-46f0-4f89-ae98-65dcabe4ef09","description":"The plugin does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"h","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"4.8","severity":"m","exploitable":"1.7","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"4.8","severity":"medium","av":"network","ac":"low","pr":"high","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"1.7","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"90dabb507dfe5144be5f0965dbe101673dea2c1f1c53a6af1fe396482aa9c321","name":"User Registration &amp; Membership &#8211; Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder [user-registration] < 3.1.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.1.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-1720","name":"CVE-2024-1720","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-1720","description":"[en] The User Registration \u2013 Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Display Name' parameter in all versions up to, and including, 3.1.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This vulnerability requires social engineering to successfully exploit, and the impact would be very limited due to the attacker requiring a user to login as the user with the injected payload for execution.","date":"2024-03-07"},{"id":"ace776b910e957666261d578d120604eec57e898","name":"User Registration \u2013 Custom Registration Form, Login Form, and User Profile WordPress Plugin <= 3.1.4 - Unauthenticated Stored Self-Based Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/user-registration\/user-registration-custom-registration-form-login-form-and-user-profile-wordpress-plugin-314-unauthenticated-stored-self-based-cross-site-scripting","description":"The User Registration \u2013 Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Display Name' parameter in all versions up to, and including, 3.1.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This vulnerability requires social engineering to successfully exploit, and the impact would be very limited due to the attacker requiring a user to login as the user with the injected payload for execution.","date":"2024-03-06"},{"id":"22256c2900c5c697ab0ba70232d3391ddad273e2","name":"WordPress  User Registration Plugin    <= 3.1.4 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/user-registration\/vulnerability\/wordpress-user-registration-plugin-3-1-4-unauthenticated-stored-self-based-cross-site-scripting-vulnerability","description":"Update the WordPress User Registration plugin to the latest available version (at least 3.1.5).\nstealthcopter discovered and reported this Cross Site Scripting (XSS) vulnerability in WordPress User Registration Plugin. This could allow a malicious actor to inject malicious scripts, such as redirects, advertisements, and other HTML payloads into your website which will be executed when guests visit your site.  This vulnerability has been fixed in version 3.1.5.\nHave additional information or questions about this entry? Get in touch.","date":null},{"id":"46dd7f7b-ea3f-4e42-8855-57d011009711","name":"User Registration &ndash; Custom Registration Form, Login Form, and User Profile WordPress Plugin &lt; 3.1.5 - Unauthenticated Stored Self-Based Cross-Site Scripting","link":"https:\/\/wpscan.com\/vulnerability\/46dd7f7b-ea3f-4e42-8855-57d011009711","description":"The User Registration &ndash; Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the &#039;Display Name&#039; parameter in all versions up to, and including, 3.1.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This vulnerability requires social engineering to successfully exploit, and the impact would be very limited due to the attacker requiring a user to login as the user with the injected payload for execution.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"7b15984a1fe35db29890062ab78f4d9012e4cc20eb4ab187f0b3693c28bab84c","name":"User Registration &amp; Membership &#8211; Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder [user-registration] < 3.2.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.2.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-3295","name":"CVE-2024-3295","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-3295","description":"[en] The User Registration \u2013 Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the profile_pic_remove function in versions up to, and including, 3.1.5. This makes it possible for unauthenticated attackers to delete any media file.","date":"2024-05-02"},{"id":"29515702b9d83609a81d1a01eb4f94465e902e99","name":"User Registration \u2013 Custom Registration Form, Login Form, and User Profile WordPress Plugin <= 3.1.5 - Missing Authorization to Unauthenticated Media Deletion","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/user-registration\/user-registration-custom-registration-form-login-form-and-user-profile-wordpress-plugin-315-missing-authorization-to-unauthenticated-media-deletion","description":"The User Registration \u2013 Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the profile_pic_remove function in versions up to, and including, 3.1.5. This makes it possible for unauthenticated attackers to delete any media file.","date":"2024-04-15"},{"id":"edb42bef9e2c327c3df87899fc24c3e7bc0e433b","name":"WordPress User Registration Plugin <= 3.1.5 is vulnerable to Broken Access Control","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/user-registration\/vulnerability\/wordpress-user-registration-plugin-3-1-5-missing-authorization-to-unauthenticated-media-deletion-vulnerability","description":"<p>WordPress User Registration Plugin <= 3.1.5 is vulnerable to Broken Access Control<\/p><p>Software: User Registration<\/p><p>Link: https:\/\/wordpress.org\/plugins\/user-registration\/#developers<\/p><p>Affected Version <= 3.1.5<\/p><p>Fixed in version 3.2.0 <\/p>","date":"2024-04-16"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:L","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"n","i":"l","a":"l","score":"6.5","severity":"m","exploitable":"3.9","impact":"2.5"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:L","score":"6.5","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"none","i":"low","a":"low","exploitable":"3.9","impact":"2.5"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"ad4c3a9e6d450dcd0363b23383768e95620bbb4be36f992acebb1fc7a0703618","name":"User Registration &amp; Membership &#8211; Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder [user-registration] < 3.2.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.2.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-2417","name":"CVE-2024-2417","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-2417","description":"[en] The User Registration \u2013 Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the form_save_action() function in all versions up to, and including, 3.1.5. This makes it possible for authenticated attackers, with subscriber-level access and above, to update the registration form and make the default registration role administrator. This subsequently allows the attacker to register an account as an administrator on the site.","date":"2024-05-02"},{"id":"77172b8e4ad6d77638e6f400c38b9d5a439edf20","name":"User Registration \u2013 Custom Registration Form, Login Form, and User Profile WordPress Plugin <= 3.1.5 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/user-registration\/user-registration-custom-registration-form-login-form-and-user-profile-wordpress-plugin-315-missing-authorization-to-authenticated-subscriber-privilege-escalation","description":"The User Registration \u2013 Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the form_save_action() function in all versions up to, and including, 3.1.5. This makes it possible for authenticated attackers, with subscriber-level access and above, to update the registration form and make the default registration role administrator. This subsequently allows the attacker to register an account as an administrator on the site.","date":"2024-04-19"},{"id":"5f0692d396b908671c3b1613db5150e51315f897","name":"WordPress User Registration Plugin <= 3.1.5 is vulnerable to Broken Access Control","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/user-registration\/vulnerability\/wordpress-user-registration-plugin-3-1-5-authenticated-subscriber-privilege-escalation-vulnerability","description":"<p>WordPress User Registration Plugin <= 3.1.5 is vulnerable to Broken Access Control<\/p><p>Software: User Registration<\/p><p>Link: https:\/\/wordpress.org\/plugins\/user-registration\/#developers<\/p><p>Affected Version <= 3.1.5<\/p><p>Fixed in version 3.2.0 <\/p>","date":"2024-04-19"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"8.8","severity":"h","exploitable":"2.8","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"8.8","severity":"high","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"2.8","impact":"5.9"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"1a28743c9674a4fcb0c02b75e29da986f1558b2f63b08078ad2cf1c6bfc2494f","name":"User Registration &amp; Membership &#8211; Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder [user-registration] < 3.2.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"3.2.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2024-4958","name":"CVE-2024-4958","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2024-4958","description":"[en] The User Registration \u2013 Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'import_form_action' function in versions up to, and including, 3.2.0.1. This makes it possible for authenticated attackers, with contributor-level permissions and above, to import a registration form with a default user role of administrator. If an administrator approves or publishes a post or page with the shortcode to the imported form, any user can register as an administrator.","date":"2024-06-01"},{"id":"e66392a60000f0c9db675439dcfbe37e1ca7e79f","name":"User Registration \u2013 Custom Registration Form, Login Form, and User Profile WordPress Plugin <= 3.2.0.1 - Missing Authorization to Privilege Escalation","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/user-registration\/user-registration-custom-registration-form-login-form-and-user-profile-wordpress-plugin-3201-missing-authorization-to-privilege-escalation","description":"The User Registration \u2013 Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'import_form_action' function in versions up to, and including, 3.2.0.1. This makes it possible for authenticated attackers, with contributor-level permissions and above, to import a registration form with a default user role of administrator. If an administrator approves or publishes a post or page with the shortcode to the imported form, any user can register as an administrator.","date":"2024-05-31"},{"id":"8198aac00e36acf0e53f5a25c50532917a3c2609","name":"WordPress User Registration Plugin <= 3.2.0.1 is vulnerable to Broken Access Control","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/user-registration\/vulnerability\/wordpress-user-registration-plugin-3-2-0-1-missing-authorization-to-privilege-escalation-vulnerability","description":"<p>WordPress User Registration Plugin <= 3.2.0.1 is vulnerable to Broken Access Control<\/p><p>Software: User Registration<\/p><p>Link: https:\/\/wordpress.org\/plugins\/user-registration\/#developers<\/p><p>Affected Version <= 3.2.0.1<\/p><p>Fixed in version 3.2.1 <\/p>","date":"2024-06-03"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:L\/UI:R\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"h","pr":"l","ui":"r","s":"u","c":"h","i":"h","a":"h","score":"7.1","severity":"h","exploitable":"1.2","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:L\/UI:R\/S:U\/C:H\/I:H\/A:H","score":"7.1","severity":"high","av":"network","ac":"high","pr":"low","ui":"required","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"1.2","impact":"5.9"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"7251eec5940b9d64a721fd4eaa6efb4aee8c0c8e168773999a9fc567a1552477","name":"User Registration &amp; Membership &#8211; Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder [user-registration] < 4.1.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.1.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-1511","name":"User Registration & Membership \u2013 Custom Registration Form, Login Form, and User Profile <= 4.0.4 - Reflected Cross-Site Scripting","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-1511","description":"The User Registration & Membership \u2013 Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 4.0.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","date":"0000-00-00"},{"id":"e1a9473c656173f2a1e284203e2c814c41599c45","name":"User Registration & Membership \u2013 Custom Registration Form, Login Form, and User Profile <= 4.0.4 - Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/user-registration\/user-registration-membership-custom-registration-form-login-form-and-user-profile-404-reflected-cross-site-scripting","description":"The User Registration & Membership \u2013 Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 4.0.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","date":"2025-02-27"},{"id":"c08b555e610b0adc44db3be36aed010804a8a145","name":"WordPress User Registration Plugin <= 4.0.4 is vulnerable to Cross Site Scripting (XSS)","link":"https:\/\/patchstack.com\/database\/wordpress\/plugin\/user-registration\/vulnerability\/wordpress-user-registration-plugin-4-0-4-reflected-cross-site-scripting-vulnerability","description":"<p>WordPress User Registration Plugin <= 4.0.4 is vulnerable to Cross Site Scripting (XSS)<\/p><p>Software: User Registration<\/p><p>Fixed in version 4.1.0 <\/p><p>Affected Version <= 4.0.4<\/p><p>CVE: CVE-2025-1511<\/p>","date":"2025-02-28"},{"id":"EUVD-2025-5475","name":"EUVD-2025-5475","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-5475","description":"The User Registration & Membership \u2013 Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 4.0.4 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","date":"2025-02-28"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null},"epss":"0.002"}},{"uuid":"18bd789f5a4db7c56ac39ef9f3cba1a280bb31c6bb604f17e09eebbc69d5b865","name":"User Registration &amp; Membership &#8211; Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder [user-registration] < 4.1.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.1.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-2563","name":"User Registration & Membership < 4.1.2- Unauthenticated Privilege Escalation","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-2563","description":"The User Registration & Membership  WordPress plugin before 4.1.2 does not prevent users to set their account role when the Membership Addon is enabled, leading to a privilege escalation issue and allowing unauthenticated users to gain admin privileges","date":"0000-00-00"},{"id":"3c410251f9ce7913cdc8c551aea7b4ad52ee348e","name":"User Registration & Membership <= 4.1.1 - Unauthenticated Privilege Escalation","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/user-registration\/user-registration-membership-411-unauthenticated-privilege-escalation","description":"The User Registration & Membership plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 4.1.1. This is due to insufficient restrictions on role type in the 'prepare_members_data()' function. This makes it possible for unauthenticated attackers to create new user accounts with the 'administrator'' role.","date":"2026-06-26"},{"id":"EUVD-2025-10866","name":"EUVD-2025-10866","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-10866","description":"The User Registration & Membership  WordPress plugin before 4.1.2 does not prevent users to set their account role when the Membership Addon is enabled, leading to a privilege escalation issue and allowing unauthenticated users to gain admin privileges","date":"2025-04-14"},{"id":"d1fa0e7022a120c7d5e2ffa786c075a77bfae7e6","name":"User Registration & Membership <= 4.1.1 - Unauthenticated Privilege Escalation","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/id\/ffd9cbd1-f8a9-401e-8cdd-1ff16f438b4a","description":"The User Registration & Membership plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 4.1.1. This is due to insufficient restrictions on role type in the 'prepare_members_data()' function. This makes it possible for unauthenticated attackers to create new user accounts with the 'administrator'' role.","date":"2025-03-24"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"h","pr":"n","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"8.1","severity":"h","exploitable":"2.2","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"8.1","severity":"high","av":"network","ac":"high","pr":"none","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"2.2","impact":"5.9"},"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"9734723f762d60cf736e31f7c0dbb70bedf517ae033f4a1a54b415aec9b02de3","name":"User Registration &amp; Membership &#8211; Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder [user-registration] < 4.0.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.0.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-30899","name":"CVE-2025-30899","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-30899","description":"[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpeverest User Registration allows Stored XSS. This issue affects User Registration: from n\/a through 4.0.3.","date":"2025-03-27"},{"id":"170d5700b7f25c946628be0a3cbac871291af012","name":"User Registration <= 4.0.3 - Authenticated (Administrator+) Stored Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/user-registration\/user-registration-403-authenticated-administrator-stored-cross-site-scripting","description":"The User Registration plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page. This only impacts multi-site installations and installations where unfiltered_html has been disabled.","date":"2025-03-27"},{"id":"EUVD-2025-8305","name":"EUVD-2025-8305","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-8305","description":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpeverest User Registration allows Stored XSS. This issue affects User Registration: from n\/a through 4.0.3.","date":"2025-03-27"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"h","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"4.8","severity":"m","exploitable":"1.7","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"4.8","severity":"medium","av":"network","ac":"low","pr":"high","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"1.7","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"3dc6f84f8c3285c3a5de9922031336fbe1a867bf252d7f351089ab4d56efca15","name":"User Registration &amp; Membership &#8211; Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder [user-registration] < 4.1.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.1.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-2594","name":"User Registration & Membership < 4.1.3 - Authentication Bypass","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-2594","description":"The User Registration & Membership WordPress plugin before 4.1.3 does not properly validate data in an AJAX action when the Membership Addon is enabled, allowing attackers to authenticate as any user, including administrators, by simply using the target account's user ID.","date":"0000-00-00"},{"id":"fc54175b8186f0bb7340095e904f394dfb5e7915","name":"User Registration & Membership <= 4.1.2 - Authentication Bypass","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/user-registration\/user-registration-membership-412-authentication-bypass","description":"The User Registration & Membership plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 4.1.2. This is due to incorrect authentication in the 'confirm_payment()' function. This makes it possible for unauthenticated attackers to log in an existing user on the site, even an administrator.","date":"2025-04-01"},{"id":"EUVD-2025-12286","name":"EUVD-2025-12286","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-12286","description":"The User Registration & Membership  WordPress plugin before 4.1.3 does not properly validate data in an AJAX action when the Membership Addon is enabled, allowing attackers to authenticate as any user, including administrators, by simply using the target account's user ID.","date":"2025-04-22"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"h","pr":"n","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"8.1","severity":"h","exploitable":"2.2","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"8.1","severity":"high","av":"network","ac":"high","pr":"none","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"2.2","impact":"5.9"},"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"total","kev":false,"kev_date":null},"epss":"0.027"}},{"uuid":"2226c57c3e79fb970a6dff5549d0a6e52e71ff521bdbbabf4b2289ad7bf4e381","name":"User Registration &amp; Membership &#8211; Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder [user-registration] < 4.1.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.1.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-3292","name":"User Registration & Membership \u2013 Custom Registration Form, Login Form, and User Profile <= 4.1.3 - Insecure Direct Object Reference to Authenticated (Subscriber+) User Password Update","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-3292","description":"The User Registration & Membership \u2013 Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.1.3 via the user_registration_update_profile_details() due to missing validation on the 'user_id' user controlled key. This makes it possible for unauthenticated attackers to update other user's passwords, if they have access to the user ID and email.","date":"0000-00-00"},{"id":"868aa3dfeebcb1940436cada2ce4b85ee303fe76","name":"User Registration & Membership \u2013 Custom Registration Form, Login Form, and User Profile <= 4.1.3 - Insecure Direct Object Reference to Authenticated (Subscriber+) User Password Update","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/user-registration\/user-registration-membership-custom-registration-form-login-form-and-user-profile-413-insecure-direct-object-reference-to-authenticated-subscriber-user-password-update","description":"The User Registration & Membership \u2013 Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.1.3 via the user_registration_update_profile_details() due to missing validation on the 'user_id' user controlled key. This makes it possible for unauthenticated attackers to update other user's passwords, if they have access to the user ID and email.","date":"2025-04-11"},{"id":"EUVD-2025-10843","name":"EUVD-2025-10843","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-10843","description":"The User Registration & Membership \u2013 Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.1.3 via the user_registration_update_profile_details() due to missing validation on the 'user_id' user controlled key. This makes it possible for unauthenticated attackers to update other user's passwords, if they have access to the user ID and email.","date":"2025-04-12"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"n","i":"l","a":"n","score":"4.3","severity":"m","exploitable":"2.8","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"2.8","impact":"1.4"},"cwe":[{"cwe":"CWE-639","name":"Authorization Bypass Through User-Controlled Key","description":"The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null},"epss":"0.001"}},{"uuid":"2684eee3e13f94040fa803c70ef531158073cd8183942b093f97dad15d5b7fc5","name":"User Registration &amp; Membership &#8211; Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder [user-registration] < 4.1.4","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.1.4","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-3282","name":"User Registration & Membership \u2013 Custom Registration Form, Login Form, and User Profile <= 4.1.3 - Insecure Direct Object Reference to Unauthenticated Membership Modification","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-3282","description":"The User Registration & Membership \u2013 Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.1.3 via the user_registration_membership_register_member() due to missing validation on the 'membership_id' user controlled key. This makes it possible for unauthenticated attackers to update any user's membership to any other active or non-active membership type.","date":"0000-00-00"},{"id":"c3e6f9390c5cc3bfcc3d57e169066f1c0beb5734","name":"User Registration & Membership \u2013 Custom Registration Form, Login Form, and User Profile <= 4.1.3 - Insecure Direct Object Reference to Unauthenticated Membership Modification","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/user-registration\/user-registration-membership-custom-registration-form-login-form-and-user-profile-413-insecure-direct-object-reference-to-unauthenticated-membership-modification","description":"The User Registration & Membership \u2013 Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.1.3 via the user_registration_membership_register_member() due to missing validation on the 'membership_id' user controlled key. This makes it possible for unauthenticated attackers to update any user's membership to any other active or non-active membership type.","date":"2025-04-11"},{"id":"EUVD-2025-10841","name":"EUVD-2025-10841","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-10841","description":"The User Registration & Membership \u2013 Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.1.3 via the user_registration_membership_register_member() due to missing validation on the 'membership_id' user controlled key. This makes it possible for unauthenticated attackers to update any user's membership to any other active or non-active membership type.","date":"2025-04-12"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"n","i":"l","a":"n","score":"5.3","severity":"m","exploitable":"3.9","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"3.9","impact":"1.4"},"cwe":[{"cwe":"CWE-639","name":"Authorization Bypass Through User-Controlled Key","description":"The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null},"epss":"0.001"}},{"uuid":"7ff7531f7e8d07f1d667d09247f277676649a3730dbab63100eb663e8e130cd1","name":"User Registration &amp; Membership &#8211; Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder [user-registration] < 4.2.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.2.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-39400","name":"CVE-2025-39400","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-39400","description":"[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpeverest User Registration allows Reflected XSS. This issue affects User Registration: from n\/a through n\/a.","date":"2025-04-24"},{"id":"297572bf6b7a5c54bf710a3ae45855d2a52be41b","name":"User Registration <= 4.1.5 - Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/user-registration\/user-registration-415-reflected-cross-site-scripting","description":"The User Registration & Membership \u2013 Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 4.1.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","date":"2025-04-22"},{"id":"EUVD-2025-12078","name":"EUVD-2025-12078","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-12078","description":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpeverest User Registration allows Reflected XSS. This issue affects User Registration: from n\/a through n\/a.","date":"2025-04-24"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"2.8","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"2.8","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"c37a345fa9d5c739baf17bb55cf47830009afb57fbd5565c91fa81b53ace0bca","name":"User Registration &amp; Membership &#8211; Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder [user-registration] < 4.2.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.2.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-3281","name":"User Registration & Membership \u2013 Custom Registration Form, Login Form, and User Profile <= 4.2.1 - Insecure Direct Object Reference to Unauthenticated Limited User Deletion","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-3281","description":"The User Registration & Membership \u2013 Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.2.1 via the create_stripe_subscription() function, due to missing validation on the 'member_id' user controlled key. This makes it possible for unauthenticated attackers to delete arbitrary user accounts that have registered through the plugin.","date":"0000-00-00"},{"id":"de68284d6ecda6161cb9f2f22e784d69861cbc3c","name":"User Registration & Membership \u2013 Custom Registration Form, Login Form, and User Profile <= 4.2.1 - Insecure Direct Object Reference to Unauthenticated Limited User Deletion","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/user-registration\/user-registration-membership-custom-registration-form-login-form-and-user-profile-421-insecure-direct-object-reference-to-unauthenticated-limited-user-deletion","description":"The User Registration & Membership \u2013 Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.2.1 via the create_stripe_subscription() function, due to missing validation on the 'member_id' user controlled key. This makes it possible for unauthenticated attackers to delete arbitrary user accounts that have registered through the plugin.","date":"2025-05-05"},{"id":"EUVD-2025-13565","name":"EUVD-2025-13565","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-13565","description":"The User Registration & Membership \u2013 Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.2.1 via the create_stripe_subscription() function, due to missing validation on the 'member_id' user controlled key. This makes it possible for unauthenticated attackers to delete arbitrary user accounts that have registered through the plugin.","date":"2025-05-06"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"n","i":"l","a":"n","score":"5.3","severity":"m","exploitable":"3.9","impact":"1.4"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"3.9","impact":"1.4"},"cwe":[{"cwe":"CWE-639","name":"Authorization Bypass Through User-Controlled Key","description":"The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null},"epss":"0.001"}},{"uuid":"32d6cdaac5e12aac9ad77825723b845b9a0ab9628213f90ae66f0e493c7fef54","name":"User Registration &amp; Membership &#8211; Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder [user-registration] < 4.3.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.3.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-6831","name":"User Registration <= 4.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via urcr_restrict Shortcode","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-6831","description":"The User Registration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's urcr_restrict shortcode in all versions up to, and including, 4.2.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"0000-00-00"},{"id":"e81c419f8bf663f814910550e65c59ecc7416a0a","name":"User Registration <= 4.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via urcr_restrict Shortcode","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/user-registration\/user-registration-424-authenticated-contributor-stored-cross-site-scripting-via-urcr-restrict-shortcode","description":"The User Registration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's urcr_restrict shortcode in all versions up to, and including, 4.2.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-07-21"},{"id":"EUVD-2025-22277","name":"EUVD-2025-22277","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2025-22277","description":"The User Registration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's urcr_restrict shortcode in all versions up to, and including, 4.2.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-07-22"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"6.4","severity":"m","exploitable":"3.1","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"6.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"3.1","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null},"epss":"0.001"}},{"uuid":"d4fb2b4dd50e8f943b7128baa6f9ef8803202da10a96b61d42bf3e2f4d3af479","name":"User Registration &amp; Membership &#8211; Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder [user-registration] < 4.4.7","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.4.7","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-13367","name":"CVE-2025-13367","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-13367","description":"[en] The User Registration & Membership \u2013 Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple shortcode attributes in all versions up to, and including, 4.4.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-12-15"},{"id":"7c3aace1ffd691cf56b5605dadfed5e57a7e388b","name":"User Registration & Membership \u2013 Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin <= 4.4.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/user-registration\/user-registration-membership-custom-registration-form-builder-custom-login-form-user-profile-content-restriction-membership-plugin-446-authenticated-contributor-stored-cross-site-scripting-via-shortcode-attributes","description":"The User Registration & Membership \u2013 Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple shortcode attributes in all versions up to, and including, 4.4.6 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.","date":"2025-12-15"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"c","c":"l","i":"l","a":"n","score":"6.4","severity":"m","exploitable":"3.1","impact":"2.7"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:C\/C:L\/I:L\/A:N","score":"6.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"changed","c":"low","i":"low","a":"none","exploitable":"3.1","impact":"2.7"},"cwe":[{"cwe":"CWE-79","name":"Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')","description":"The product does not neutralize or incorrectly neutralizes user-controllable input before it is placed in output that is used as a web page that is served to other users."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"24b931abb775c87c965f6682cb2c2a21b06c048451a2f4ab210fb367c90ffd65","name":"User Registration &amp; Membership &#8211; Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder [user-registration] < 4.4.9","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.4.9","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-14976","name":"CVE-2025-14976","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-14976","description":"[en] The User Registration & Membership \u2013 Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.4.8. This is due to missing or incorrect nonce validation on the 'process_row_actions' function with the 'delete' action. This makes it possible for unauthenticated attackers to delete arbitrary post via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2026-01-10"},{"id":"0411d3f350d110c90cb2a787cd19e27ccf719a8c","name":"User Registration & Membership <= 4.4.8 - Cross-Site Request Forgery to Arbitrary Post Deletion","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/user-registration\/user-registration-membership-448-cross-site-request-forgery-to-arbitrary-post-deletion","description":"The User Registration & Membership \u2013 Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.4.8. This is due to missing or incorrect nonce validation on the 'process_row_actions' function with the 'delete' action. This makes it possible for unauthenticated attackers to delete arbitrary post via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2026-01-09"},{"id":"EUVD-2026-1857","name":"EUVD-2026-1857","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2026-1857","description":"The User Registration & Membership \u2013 Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.4.8. This is due to missing or incorrect nonce validation on the 'process_row_actions' function with the 'delete' action. This makes it possible for unauthenticated attackers to delete arbitrary post via a forged request granted they can trick a site administrator into performing an action such as clicking on a link.","date":"2026-01-10"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:L","av":"n","ac":"l","pr":"n","ui":"r","s":"u","c":"n","i":"l","a":"l","score":"5.4","severity":"m","exploitable":"2.8","impact":"2.5"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:U\/C:N\/I:L\/A:L","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"unchanged","c":"none","i":"low","a":"low","exploitable":"2.8","impact":"2.5"},"cwe":[{"cwe":"CWE-352","name":"Cross-Site Request Forgery (CSRF)","description":"The web application does not, or cannot, sufficiently verify whether a request was intentionally provided by the user who sent the request, which could have originated from an unauthorized actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"7d8bde75fd25d81c02bafbcfdb8e406d4053e58f62ad14cee9498ba18ebdc417","name":"User Registration &amp; Membership &#8211; Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder [user-registration] < 4.4.7","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.4.7","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-67956","name":"CVE-2025-67956","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-67956","description":"[en] Missing Authorization vulnerability in wpeverest User Registration user-registration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects User Registration: from n\/a through <= 4.4.6.","date":"2026-01-22"},{"id":"cf2265d8f77cd4ae1c8d18d145e17d6e8647926c","name":"User Registration <= 4.4.6 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/user-registration\/user-registration-446-missing-authorization","description":"The User Registration & Membership \u2013 Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.4.6. This makes it possible for unauthenticated attackers to perform an unauthorized action.","date":"2026-01-21"},{"id":"EUVD-2026-4027","name":"EUVD-2026-4027","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2026-4027","description":"Missing Authorization vulnerability in wpeverest User Registration user-registration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects User Registration: from n\/a through <= 4.4.6.","date":"2026-01-22"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:H\/A:L","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"n","i":"h","a":"l","score":"8.2","severity":"h","exploitable":"3.9","impact":"4.2"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:H\/A:L","score":"8.2","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"none","i":"high","a":"low","exploitable":"3.9","impact":"4.2"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"199c18beb17ad5f394418ee00b47666b4dd1d2dec8634158767710330bed51df","name":"User Registration &amp; Membership &#8211; Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder [user-registration] < 5.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-24353","name":"CVE-2026-24353","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-24353","description":"[en] Missing Authorization vulnerability in wpeverest User Registration user-registration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects User Registration: from n\/a through <= 4.4.9.","date":"2026-01-22"},{"id":"fb115e4bb4591163a99ab2fb64a7602adcb87985","name":"User Registration <= 4.4.9 - Authenticated (Subscriber+) Arbitrary Shortcode Execution","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/user-registration\/user-registration-449-authenticated-subscriber-arbitrary-shortcode-execution","description":"The The User Registration & Membership \u2013 Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.4.9. This is due to the software allowing users to execute an action that does not properly validate a value before running do_shortcode. This makes it possible for authenticated attackers, with Subscriber-level access and above, to execute arbitrary shortcodes.","date":"2026-01-08"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"4.3","severity":"m","exploitable":"2.8","impact":"5.2"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"2.8","impact":"5.2"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"f1eec1152e6a51e0493c4733a74f921572917ce7b4d892eb4a017ce55d38e66f","name":"User Registration &amp; Membership &#8211; Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder [user-registration] < 5.1.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.1.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-32488","name":"CVE-2026-32488","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-32488","description":"[en] Incorrect Privilege Assignment vulnerability in wpeverest User Registration user-registration allows Privilege Escalation.This issue affects User Registration: from n\/a through <= 4.4.9.","date":"2026-03-25"},{"id":"164746b849fbada76fc1e4e128bce8039e4de569","name":"User Registration & Membership \u2013 Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder <= 4.4.9 - Unauthenticated Remote Code Execution","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/user-registration\/user-registration-membership-free-paid-memberships-subscriptions-content-restriction-user-profile-custom-user-registration-login-builder-449-unauthenticated-remote-code-execution","description":"The User Registration & Membership \u2013 Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.4.9. This makes it possible for unauthenticated attackers to execute code on the server.","date":"2026-03-23"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","av":"n","ac":"h","pr":"n","ui":"n","s":"u","c":"h","i":"h","a":"h","score":"8.1","severity":"h","exploitable":"2.2","impact":"5.9"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:H\/PR:N\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"8.1","severity":"high","av":"network","ac":"high","pr":"none","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":"2.2","impact":"5.9"},"cwe":[{"cwe":"CWE-266","name":"Incorrect Privilege Assignment","description":"A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"8c31ffe2a34ba32106d38c0424422b63e5353ee7b50a960d7d6107d191e6e9c8","name":"User Registration &amp; Membership &#8211; Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder [user-registration] < 5.1.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.1.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-1865","name":"User Registration & Membership <= 5.1.2 - Authenticated (Subscriber+) SQL Injection via membership_ids[]","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-1865","description":"The User Registration & Membership \u2013 Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to SQL Injection via the \u2018membership_ids[]\u2019 parameter in all versions up to, and including, 5.1.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":"0000-00-00"},{"id":"5793cdd1e0aa7d4a756fb8005ceab87501df6ab3","name":"User Registration & Membership <= 5.1.2 - Authenticated (Subscriber+) SQL Injection via membership_ids[]","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/user-registration\/user-registration-membership-512-authenticated-subscriber-sql-injection-via-membership-ids","description":"The User Registration & Membership \u2013 Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to SQL Injection via the \u2018membership_ids[]\u2019 parameter in all versions up to, and including, 5.1.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":"2026-04-07"},{"id":"EUVD-2026-20444","name":"EUVD-2026-20444","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2026-20444","description":"The User Registration & Membership \u2013 Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to SQL Injection via the \u2018membership_ids[]\u2019 parameter in all versions up to, and including, 5.1.2 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query.  This makes it possible for authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":"2026-04-08"}],"impact":{"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:H\/I:N\/A:N","score":"6.5","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"high","i":"none","a":"none","exploitable":null,"impact":null}}},{"uuid":"8cf3a742670e57e53d6bf8e7593d7445644a38a36142359d5b88a218c2b73d2d","name":"User Registration &amp; Membership &#8211; Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder [user-registration] < 5.1.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.1.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-4056","name":"User Registration & Membership <= 5.1.4 - Missing Authorization to Authenticated (Contributor+) Content Access Rule Manipulation","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-4056","description":"The User Registration & Membership plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Content Access Rules REST API endpoints in versions 5.0.1 through 5.1.4. This is due to the `check_permissions()` method only checking for `edit_posts` capability instead of an administrator-level capability. This makes it possible for authenticated attackers, with Contributor-level access and above, to list, create, modify, toggle, duplicate, and delete site-wide content restriction rules, potentially exposing restricted content or denying legitimate user access.","date":"0000-00-00"},{"id":"59a13905a24f5898a0f098e3f78e1bbd08ec4494","name":"User Registration & Membership <= 5.1.4 - Missing Authorization to Authenticated (Contributor+) Content Access Rule Manipulation","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/user-registration\/user-registration-membership-514-missing-authorization-to-authenticated-contributor-content-access-rule-manipulation","description":"The User Registration & Membership plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Content Access Rules REST API endpoints in versions 5.0.1 through 5.1.4. This is due to the `check_permissions()` method only checking for `edit_posts` capability instead of an administrator-level capability. This makes it possible for authenticated attackers, with Contributor-level access and above, to list, create, modify, toggle, duplicate, and delete site-wide content restriction rules, potentially exposing restricted content or denying legitimate user access.","date":"2026-03-23"}],"impact":{"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"49de01df25be69cd553e04f01f6f3d09800eae4b7254a902fb2289d9329db133","name":"User Registration &amp; Membership &#8211; Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder [user-registration] < 5.1.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.1.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-6203","name":"CVE-2026-6203","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-6203","description":"[en] The User Registration & Membership plugin for WordPress is vulnerable to Open Redirect in versions up to and including 5.1.4. This is due to insufficient validation of user-supplied URLs passed via the 'redirect_to_on_logout' GET parameter before redirecting users. The `redirect_to_on_logout` GET parameter is passed directly to WordPress's `wp_redirect()` function instead of the domain-restricted `wp_safe_redirect()`. While `esc_url_raw()` is applied to sanitize malformed URLs, it does not restrict the redirect destination to the local domain, allowing an attacker to craft a specially formed link that redirects users to potentially malicious external URLs after logout, which could be used to facilitate phishing attacks.","date":"2026-04-13"},{"id":"ec2244f6ce5f2e366394d2a8561334d68fec2895","name":"User Registration & Membership <= 5.1.4 - Unauthenticated Open Redirect via 'redirect_to_on_logout' Parameter","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/user-registration\/user-registration-membership-514-unauthenticated-open-redirect-via-redirect-to-on-logout-parameter","description":"The User Registration & Membership plugin for WordPress is vulnerable to Open Redirect in versions up to and including 5.1.4. This is due to insufficient validation of user-supplied URLs passed via the 'redirect_to_on_logout' GET parameter before redirecting users. The `redirect_to_on_logout` GET parameter is passed directly to WordPress's `wp_redirect()` function instead of the domain-restricted `wp_safe_redirect()`. While `esc_url_raw()` is applied to sanitize malformed URLs, it does not restrict the redirect destination to the local domain, allowing an attacker to craft a specially formed link that redirects users to potentially malicious external URLs after logout, which could be used to facilitate phishing attacks.","date":"2026-04-13"},{"id":"EUVD-2026-22135","name":"EUVD-2026-22135","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2026-22135","description":"The User Registration & Membership plugin for WordPress is vulnerable to Open Redirect in versions up to and including 5.1.4. This is due to insufficient validation of user-supplied URLs passed via the 'redirect_to_on_logout' GET parameter before redirecting users. The `redirect_to_on_logout` GET parameter is passed directly to WordPress's `wp_redirect()` function instead of the domain-restricted `wp_safe_redirect()`. While `esc_url_raw()` is applied to sanitize malformed URLs, it does not restrict the redirect destination to the local domain, allowing an attacker to craft a specially formed link that redirects users to potentially malicious external URLs after logout, which could be used to facilitate phishing attacks.","date":"2026-04-14"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"n","score":"6.1","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:N","score":"6.1","severity":"medium","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-601","name":"URL Redirection to Untrusted Site ('Open Redirect')","description":"The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"7d2cd2cc026abf2fa253d0730b23a77b56fd6e372d593080e6d81b45a85234fe","name":"User Registration &amp; Membership &#8211; Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder [user-registration] < 5.1.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.1.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-1492","name":"User Registration & Membership <= 5.1.2 - Unauthenticated Privilege Escalation via Membership Registration","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-1492","description":"The User Registration & Membership \u2013 Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to improper privilege management in all versions up to, and including, 5.1.2. This is due to the plugin accepting a user-supplied role during membership registration without properly enforcing a server-side allowlist. This makes it possible for unauthenticated attackers to create administrator accounts by supplying a role value during membership registration.","date":"0000-00-00"},{"id":"f4911ced40189e33b64a91ca0579be01b2050595","name":"User Registration & Membership <= 5.1.2 - Unauthenticated Privilege Escalation via Membership Registration","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/user-registration\/user-registration-membership-512-unauthenticated-privilege-escalation-via-membership-registration","description":"The User Registration & Membership \u2013 Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to improper privilege management in all versions up to, and including, 5.1.2. This is due to the plugin accepting a user-supplied role during membership registration without properly enforcing a server-side allowlist. This makes it possible for unauthenticated attackers to create administrator accounts by supplying a role value during membership registration.","date":"2026-03-02"}],"impact":{"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"b20afbb32afdf9272bd3c2edae1aa44c43cdcda133f118f4a8fddaf16521cc23","name":"User Registration &amp; Membership &#8211; Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder [user-registration] < 5.1.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.1.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-1779","name":"User Registration & Membership <= 5.1.2 - Authentication Bypass","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-1779","description":"The User Registration & Membership plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.1.2. This is due to incorrect authentication in the 'register_member' function. This makes it possible for unauthenticated attackers to log in a newly registered user on the site who has the 'urm_user_just_created' user meta set.","date":"0000-00-00"},{"id":"84f8b29a9d0387d3b59af4605f1ec17fb8757cdd","name":"User Registration & Membership <= 5.1.2 - Authentication Bypass","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/user-registration\/user-registration-membership-512-authentication-bypass","description":"The User Registration & Membership plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.1.2. This is due to incorrect authentication in the 'register_member' function. This makes it possible for unauthenticated attackers to log in a newly registered user on the site who has the 'urm_user_just_created' user meta set.","date":"2026-02-25"}],"impact":{"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"ad05525a3fe7bf2f9daa6967eb2aefa78e0793a0820d11e4b955a52e9fd214b0","name":"User Registration &amp; Membership &#8211; Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder [user-registration] < 5.1.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.1.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-2356","name":"User Registration & Membership <= 5.1.2 - Insecure Direct Object Reference to Unauthenticated Limited User Deletion","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-2356","description":"The User Registration & Membership \u2013 Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.2 via the 'register_member' function, due to missing validation on the 'member_id' user controlled key. This makes it possible for unauthenticated attackers to delete arbitrary user accounts that newly registered on the site who has the 'urm_user_just_created' user meta set.","date":"0000-00-00"},{"id":"f7b03d6a4b764b1b0f6a759db237c11a15e7b461","name":"User Registration & Membership <= 5.1.2 - Insecure Direct Object Reference to Unauthenticated Limited User Deletion","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/user-registration\/user-registration-membership-512-insecure-direct-object-reference-to-unauthenticated-limited-user-deletion","description":"The User Registration & Membership \u2013 Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.2 via the 'register_member' function, due to missing validation on the 'member_id' user controlled key. This makes it possible for unauthenticated attackers to delete arbitrary user accounts that newly registered on the site who has the 'urm_user_just_created' user meta set.","date":"2026-02-25"}],"impact":{"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"1ee16b8bcd753ed7e6ec56b8c4a9ee9e7bf4ae3148acd8ce0be2b1f14f68996c","name":"User Registration &amp; Membership &#8211; Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder [user-registration] < 4.4.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"4.4.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2025-9085","name":"User Registration & Membership <= 4.3.0 - Authenticated (Admin+) SQL Injection","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2025-9085","description":"The User Registration & Membership plugin for WordPress is vulnerable to SQL Injection via the 's' parameter in version 4.3.0. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":"0000-00-00"},{"id":"e5678f0617b28f95c68b5e3a31f3cc7c271b5a43","name":"User Registration & Membership <= 4.3.0 - Authenticated (Admin+) SQL Injection","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/user-registration\/user-registration-membership-430-authenticated-admin-sql-injection","description":"The User Registration & Membership plugin for WordPress is vulnerable to SQL Injection via the 's' parameter in version 4.3.0. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with administrator-level access and above, to append additional SQL queries into already existing queries that can be used to extract sensitive information from the database.","date":"2025-09-05"}],"impact":{"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"1bd66af8559ef7cdefbabc77fe61bdf1d6e0cddd24248ca6a78ea135fdbc78f9","name":"User Registration &amp; Membership &#8211; Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder [user-registration] < 5.1.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.1.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-42652","name":"CVE-2026-42652","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-42652","description":"[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpeverest User Registration user-registration allows Reflected XSS.This issue affects User Registration: from n\/a through <= 5.1.5.","date":"2026-04-29"},{"id":"bd2f69aa24b4dac5f470e48a7f64aafbf9a155f3","name":"User Registration <= 5.1.5 - Reflected Cross-Site Scripting","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/user-registration\/user-registration-515-reflected-cross-site-scripting","description":"The User Registration plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 5.1.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successfully trick a user into performing an action such as clicking on a link.","date":"2026-04-09"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:L","av":"n","ac":"l","pr":"n","ui":"r","s":"c","c":"l","i":"l","a":"l","score":"7.1","severity":"h","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:R\/S:C\/C:L\/I:L\/A:L","score":"7.1","severity":"high","av":"network","ac":"low","pr":"none","ui":"required","s":"changed","c":"low","i":"low","a":"low","exploitable":"0.0","impact":"0.0"},"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"68ad26e3a645ac95634d42210d5ebab7fe6ec8f21a3332ec4e546be9ad001104","name":"User Registration &amp; Membership &#8211; Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder [user-registration] < 5.1.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.1.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-3601","name":"CVE-2026-3601","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-3601","description":"[en] The User Registration & Membership plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `embed_form_action()` function in all versions up to, and including, 5.1.4. This makes it possible for authenticated attackers, with Contributor-level access and above, to append shortcode content to arbitrary pages they do not own or have permission to edit.","date":"2026-05-05"},{"id":"bf916a6732e1c6687b6289bcce6cdfca8474d1cf","name":"User Registration & Membership <= 5.1.4 - Missing Authorization to Authenticated (Contributor+) Limited Page Content Modification","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/user-registration\/user-registration-membership-514-missing-authorization-to-authenticated-contributor-limited-page-content-modification","description":"The User Registration & Membership plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `embed_form_action()` function in all versions up to, and including, 5.1.4. This makes it possible for authenticated attackers, with Contributor-level access and above, to append shortcode content to arbitrary pages they do not own or have permission to edit.","date":"2026-05-04"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"n","i":"l","a":"n","score":"4.3","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:N","score":"4.3","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"94f1c3f541ce8b0a06751d4de22b0d2704cb14646be07e8f24bb4fa9f381b6cb","name":"User Registration &amp; Membership &#8211; Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder [user-registration] < 5.1.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.1.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-6145","name":"CVE-2026-6145","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-6145","description":"[en] The User Registration & Membership plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 5.1.5. This is due to the is_admin_creation_process() method relying solely on the presence of action=createuser in the $_REQUEST superglobal without performing any authentication or capability check. This makes it possible for unauthenticated attackers to bypass the admin approval requirement when registering new accounts via the fallback submission path.","date":"2026-05-14"},{"id":"8eba2973dfb67db8c07c0db7da17b78c93b1d16e","name":"User Registration & Membership <= 5.1.5 - Unauthenticated Missing Authorization to Admin Approval Bypass via 'action' Parameter","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/user-registration\/user-registration-membership-515-unauthenticated-missing-authorization-to-admin-approval-bypass-via-action-parameter","description":"The User Registration & Membership plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 5.1.5. This is due to the is_admin_creation_process() method relying solely on the presence of action=createuser in the $_REQUEST superglobal without performing any authentication or capability check. This makes it possible for unauthenticated attackers to bypass the admin approval requirement when registering new accounts via the fallback submission path.","date":"2026-05-13"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"n","i":"l","a":"n","score":"5.3","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"29cc01d363b12e520ea951c095d9394fa2af5a32afc0abca1d9f2de57a2f8f69","name":"User Registration &amp; Membership &#8211; Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder [user-registration] < 5.1.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.1.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-7651","name":"CVE-2026-7651","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-7651","description":"[en] The User Registration & Membership \u2013 Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.5. This is due to missing ownership validation on a user-controlled attachment ID, allowing the plugin to store and subsequently delete arbitrary media attachments without verifying that the referenced attachment belongs to the requesting user. This makes it possible for authenticated attackers, with subscriber-level access and above, to permanently delete arbitrary media attachments uploaded by any other user, including administrators.","date":"2026-05-28"},{"id":"a3fdd1c44e48c9d48579a4e9a8378add5ff80d24","name":"User Registration & Membership <= 5.1.5 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Media Deletion via 'profile-pic-url' Parameter","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/user-registration\/user-registration-membership-515-authenticated-subscriber-insecure-direct-object-reference-to-arbitrary-media-deletion-via-profile-pic-url-parameter","description":"The User Registration & Membership \u2013 Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.5. This is due to missing ownership validation on a user-controlled attachment ID, allowing the plugin to store and subsequently delete arbitrary media attachments without verifying that the referenced attachment belongs to the requesting user. This makes it possible for authenticated attackers, with subscriber-level access and above, to permanently delete arbitrary media attachments uploaded by any other user, including administrators.","date":"2026-05-27"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"n","i":"l","a":"n","score":"5.3","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-639","name":"Authorization Bypass Through User-Controlled Key","description":"The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"4ef51909f5ea5f7b89a82c333f625f322ffd52ac9a41caff47e29a15df6954b9","name":"User Registration &amp; Membership &#8211; Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder [user-registration] < 5.1.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.1.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-25425","name":"CVE-2026-25425","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-25425","description":"[en] Unauthenticated Broken Access Control in User Registration <= 5.1.2 versions.","date":"2026-06-15"},{"id":"d96dd20159bbac063f77394c5a66e41ae2715874","name":"User Registration & Membership \u2013 Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder <= 5.1.2 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/user-registration\/user-registration-membership-free-paid-memberships-subscriptions-content-restriction-user-profile-custom-user-registration-login-builder-512-missing-authorization","description":"The User Registration & Membership \u2013 Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 5.1.2. This makes it possible for unauthenticated attackers to perform an unauthorized action.","date":"2026-05-28"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:N\/A:H","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"n","i":"n","a":"h","score":"7.5","severity":"h","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:N\/A:H","score":"7.5","severity":"high","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"none","i":"none","a":"high","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"3d8fe0a96060a73bf9eeb4ee51dd2219cdf76303b647671ab9fcc67b74d8b21f","name":"User Registration &amp; Membership &#8211; Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder [user-registration] < 5.2.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.2.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-52701","name":"CVE-2026-52701","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-52701","description":"[en] Unauthenticated Broken Access Control in User Registration <= 5.2.2 versions.","date":"2026-06-26"},{"id":"552c8b7a204a8a8a2b2c010b09b66324ebadde06","name":"User Registration & Membership \u2013 Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder <= 5.2.2 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/user-registration\/user-registration-membership-free-paid-memberships-subscriptions-content-restriction-user-profile-custom-user-registration-login-builder-522-missing-authorization","description":"The User Registration & Membership \u2013 Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 5.2.2. This makes it possible for unauthenticated attackers to perform an unauthorized action.","date":"2026-06-22"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"l","i":"l","a":"n","score":"6.5","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:L\/A:N","score":"6.5","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"low","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"e8bc769bb526d49e0ba86a5bbf8507a4f9978aed591345f2f35ecb7211e9c8ac","name":"User Registration &amp; Membership &#8211; Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder [user-registration] < 5.2.1","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.2.1","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-1869","name":"CVE-2026-1869","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-1869","description":"[en] The User Registration & Membership \u2013 Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to unauthorized modification of data due to missing validation checks in the confirm_payment() function in all versions up to, and including, 5.2.0. This makes it possible for unauthenticated attackers to bypass payment processing and activate paid memberships.","date":"2026-06-26"},{"id":"c0d258c2cf36e1750436acb47b162bc55ff11272","name":"User Registration & Membership <= 5.2.0 - Missing Authorization to Unauthenticated Payment Bypass","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/user-registration\/user-registration-membership-520-missing-authorization-to-unauthenticated-payment-bypass","description":"The User Registration & Membership \u2013 Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to unauthorized modification of data due to missing validation checks in the confirm_payment() function in all versions up to, and including, 5.2.0. This makes it possible for unauthenticated attackers to bypass payment processing and activate paid memberships.","date":"2026-06-25"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"l","i":"l","a":"n","score":"6.5","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:L\/A:N","score":"6.5","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"low","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"19c81dd423bf892d01e82e498ccc9c2095f31efb33bc1838fe34ddac6f342252","name":"User Registration &amp; Membership &#8211; Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder [user-registration] < 5.2.0","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.2.0","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-11965","name":"CVE-2026-11965","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-11965","description":"[en] The User Registration & Membership  WordPress plugin before 5.2.0 does not enforce payment completion before activating a paid membership subscription, allowing unauthenticated users (after self-registering an account through the open registration flow) to obtain an active subscription on any paid plan without paying and access the gated content.","date":"2026-07-02"}],"impact":{"cwe":[{"cwe":"CWE-287","name":"Improper Authentication","description":"When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct."}],"ssvc":{"exploitation":"poc","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"f8843739c5284d491b27d58c12a430eca6bdd0d8436425b28b86e18edde4ab1c","name":"User Registration &amp; Membership &#8211; Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder [user-registration] < 5.2.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.2.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-11964","name":"CVE-2026-11964","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-11964","description":"[en] The User Registration & Membership  WordPress plugin before 5.2.2 does not verify the authenticity of incoming payment-provider webhook notifications before acting on them, allowing unauthenticated attackers to forge a payment-approved event and activate a paid membership subscription without completing a real payment.","date":"2026-07-13"},{"id":"a17b6f340e2dacc6b7f7b6d4cf11605e8f02adc3","name":"User Registration & Membership <= 5.2.1 - Unauthenticated PayPal Bypass to Membership Activation","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/user-registration\/user-registration-membership-521-unauthenticated-paypal-bypass-to-membership-activation","description":"The User Registration & Membership \u2013 Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to payment bypass in all versions up to, and including, 5.2.1. This makes it possible for unauthenticated attackers to activate their membership without fully completing a payment.","date":"2026-06-22"}],"impact":{"cwe":[{"cwe":"CWE-287","name":"Improper Authentication","description":"When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct."}],"ssvc":{"exploitation":"poc","automatable":"yes","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"3cf5ec348c15806001b56efc57efcff5c937b5919ab3023cb94fef242ec28c91","name":"User Registration &amp; Membership &#8211; Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder [user-registration] < 5.2.2","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.2.2","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-11963","name":"CVE-2026-11963","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-11963","description":"[en] The User Registration & Membership  WordPress plugin before 5.2.2 does not perform an authorization check on a membership-upgrade action and derives the user to modify from a caller-supplied identifier instead of the current user, allowing any authenticated user such as a subscriber to change another user's WordPress role and membership tier.","date":"2026-07-13"},{"id":"112252d0d0e2b6fa678a644881b3e209c7025d75","name":"User Registration & Membership <= 5.2.1 - Authenticated (Subscriber+) Insecure Direct Object Reference to Membership Tier Modification","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/user-registration\/user-registration-membership-521-authenticated-subscriber-insecure-direct-object-reference-to-membership-tier-modification","description":"The User Registration & Membership \u2013 Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.2.1 due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with Subscriber-level access and above, to register as other membership tiers.","date":"2026-06-22"}],"impact":{"cwe":[{"cwe":"CWE-639","name":"Authorization Bypass Through User-Controlled Key","description":"The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data."}],"ssvc":{"exploitation":"poc","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"2693eff5092cbcae5a0bbd4efc412b3aa9bdc4dfaae2b3e40a63e74bba0d6ec4","name":"User Registration &amp; Membership &#8211; Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder [user-registration] < 5.2.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.2.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-11961","name":"CVE-2026-11961","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-11961","description":"[en] The User Registration & Membership  WordPress plugin before 5.2.3 does not validate that the membership tier submitted during public registration is one of the tiers allowed by the registration form before assigning that tier's associated user role, allowing unauthenticated users to register into an arbitrary published membership tier and obtain its role \u2014 up to administrator when such a tier exists.","date":"2026-07-17"},{"id":"d48300dcbfb49b9e5d9029656c8d7f4f32c7b059","name":"User Registration & Membership <= 5.2.2 - Unauthenticated Privilege Escalation","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/id\/fe3522ff-3eed-4b6a-910a-509b8963e992","description":"The User Registration & Membership \u2013 Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.2.2. This makes it possible for unauthenticated attackers to register as administrators when a site administrator has explicitly created a membership role with admin capabilities. This is not something we consider a vulnerability, and was rejected by our team.","date":"2026-06-26"}],"impact":{"cwe":[{"cwe":"CWE-269","name":"Improper Privilege Management","description":"The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"91525c19816b3be5f0f639ed7deca03b27b72d865814bc8bcd7ce41ec3c54b6e","name":"User Registration &amp; Membership &#8211; Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder [user-registration] < 5.2.3","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.2.3","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-11966","name":"CVE-2026-11966","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-11966","description":"[en] The User Registration & Membership  WordPress plugin before 5.2.3 does not perform a capability check for unauthenticated callers on one of its membership payment actions and acts on a caller-supplied user identifier, allowing unauthenticated attackers to delete recently-registered, payment-pending user accounts.","date":"2026-07-17"},{"id":"efa828ae0ed890c118368fd4971ce53be555dae2","name":"User Registration & Membership <= 5.2.2 - Missing Authorization to Unauthenticated User Deletion via Stripe Handler","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/user-registration\/user-registration-membership-522-missing-authorization-to-unauthenticated-user-deletion-via-stripe-handler","description":"The User Registration & Membership \u2013 Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.2.2. This makes it possible for unauthenticated attackers to delete users.","date":"2026-06-26"}],"impact":{"cwe":[{"cwe":"CWE-639","name":"Authorization Bypass Through User-Controlled Key","description":"The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data."}],"ssvc":{"exploitation":"poc","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"853cc840a83719c975278aa07d1ce709fd410602b7c9c209fdd600956912ebfb","name":"User Registration &amp; Membership &#8211; Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder [user-registration] < 5.2.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.2.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-16736","name":"CVE-2026-16736","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-16736","description":"[en] The User Registration & Membership  WordPress plugin before 5.2.6 does not enforce the site's registration-disabled setting when processing registration-form submissions, allowing unauthenticated users to create new accounts even when the administrator has turned off open registration.","date":"2026-08-05"}],"impact":{"cwe":[{"cwe":"CWE-284","name":"Improper Access Control","description":"The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor."}],"ssvc":{"exploitation":"poc","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"4e8bffc0171be7a7cb061a81eb1a3bbd57fea69d69590076fe70c52041a9d8d2","name":"User Registration &amp; Membership &#8211; Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder [user-registration] < 5.2.7","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.2.7","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-73403","name":"CVE-2026-73403","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-73403","description":"[en] Unauthenticated Broken Access Control in User Registration <= 5.2.6 versions.","date":"2026-08-13"},{"id":"975fcbdb2fd2a0f8042af20cb5c9e4bac8b7830c","name":"User Registration & Membership \u2013 Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder <= 5.2.6 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/id\/cbcec789-62b1-4858-a746-8034ff988458","description":"The User Registration & Membership \u2013 Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 5.2.6. This makes it possible for unauthenticated attackers to perform an unauthorized action.","date":"2026-08-13"},{"id":"1c6ab244175f3337202c402fc9e758fb67a65a40","name":"User Registration &amp; Membership \u2013 Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder &lt;= 5.2.6 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/user-registration\/user-registration-membership-free-paid-memberships-subscriptions-content-restriction-user-profile-custom-user-registration-login-builder-526-missing-authorization","description":"The User Registration &amp; Membership \u2013 Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 5.2.6. This makes it possible for unauthenticated attackers to perform an unauthorized action.","date":null}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"n","i":"l","a":"n","score":"5.3","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:N\/I:L\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"none","i":"low","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"a4299bbfb2575392e05938327002463b36a19f6e8234d69191ee2beb51c0886f","name":"User Registration &amp; Membership &#8211; Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder [user-registration] < 5.2.7","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.2.7","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-73995","name":"CVE-2026-73995","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-73995","description":"[en] Subscriber Broken Authentication in User Registration <= 5.2.6 versions.","date":"2026-08-18"},{"id":"62f6fe7387e10fdfd6b3ac7664867616e66a105f","name":"User Registration & Membership \u2013 Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder <= 5.2.6 - Missing Authorization","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/user-registration\/user-registration-membership-free-paid-memberships-subscriptions-content-restriction-user-profile-custom-user-registration-login-builder-526-missing-authorization-2","description":"The User Registration & Membership \u2013 Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 5.2.6. This makes it possible for authenticated attackers, with Subscriber-level access and above, to perform an unauthorized action.","date":"2026-08-13"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:L","av":"n","ac":"l","pr":"l","ui":"n","s":"u","c":"n","i":"l","a":"l","score":"5.4","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:L\/UI:N\/S:U\/C:N\/I:L\/A:L","score":"5.4","severity":"medium","av":"network","ac":"low","pr":"low","ui":"none","s":"unchanged","c":"none","i":"low","a":"low","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-290","name":"Authentication Bypass by Spoofing","description":"This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"fd5d5fcc91fb76aabd8291f482cac91ee6743032cd56e83fbabd2c33f0596512","name":"User Registration &amp; Membership &#8211; Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder [user-registration] < 5.2.6","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.2.6","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-79996","name":"CVE-2026-79996","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-79996","description":"[en] The User Registration & Membership  WordPress plugin before 5.2.6 does not perform a capability check when saving its login settings, allowing authenticated users who have been granted a User Registration & Membership  WordPress plugin before 5.2.6 management capability but not full administrator access to change arbitrary site options and escalate their privileges to administrator.","date":"2026-08-28"},{"id":"4a5e748e332d2bc10359ebdf6433db0e368d791f","name":"User Registration & Membership \u2013 Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder < 5.2.6 - Authenticated (Custom Role+) Privilege Escalation","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/user-registration\/user-registration-membership-free-paid-memberships-subscriptions-content-restriction-user-profile-custom-user-registration-login-builder-526-authenticated-custom-role-privilege-escalation","description":"The User Registration & Membership \u2013 Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to 5.2.6. This is due to insufficient restriction on the capabilities a user may grant themselves. This makes it possible for authenticated attackers, with custom role-level access and above, to elevate their privileges beyond those intended for their role.","date":"2026-08-28"}],"impact":{"cwe":[{"cwe":"CWE-269","name":"Improper Privilege Management","description":"The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"4173c7250fc9bd7c5a7428f6008e8a1e463c56d88ca13cbb4799e6462a3703d2","name":"User Registration &amp; Membership &#8211; Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder [user-registration] < 5.2.5","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.2.5","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-79995","name":"CVE-2026-79995","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-79995","description":"[en] The User Registration & Membership  WordPress plugin before 5.2.5 does not verify that the account whose pending email change is being cancelled belongs to the user making the request, allowing authenticated users with Subscriber-level access and above to cancel any other user's in-progress email change, including an administrator's.","date":"2026-08-28"},{"id":"82260c26fef5d3667a83a226a4ff47e9cddb3ac8","name":"User Registration & Membership \u2013 Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder < 5.2.5 - Authenticated (Subscriber+) Insecure Direct Object Reference","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/user-registration\/user-registration-membership-free-paid-memberships-subscriptions-content-restriction-user-profile-custom-user-registration-login-builder-525-authenticated-subscriber-insecure-direct-object-reference","description":"The User Registration & Membership \u2013 Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to 5.2.5. This is due to missing validation on a user controlled key. This makes it possible for authenticated attackers, with subscriber-level access and above, to perform an unauthorized action.","date":"2026-08-28"}],"impact":{"cwe":[{"cwe":"CWE-639","name":"Authorization Bypass Through User-Controlled Key","description":"The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"8cef2673ec2bf4cb1073f4125a1592d6aa4d99192997425a3f6843dca27f8e6c","name":"User Registration &amp; Membership &#8211; Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder [user-registration] < 5.2.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.2.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-86407","name":"CVE-2026-86407","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-86407","description":"[en] The User Registration & Membership  WordPress plugin before 5.2.8 does not verify that the visitor requesting its membership confirmation page owns the account named in the request, nor that any registration or purchase has taken place, allowing unauthenticated users to retrieve another user's email address, profile fields, role and membership order details. Exploitation requires the site owner to have added a user smart tag to that page's configurable message, which the shipped default does not contain.","date":"2026-09-13"},{"id":"44d98c09c1493349393f15c31c7236c2cb93e564","name":"User Registration & Membership \u2013 Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder 5.0 - 5.2.7 - Unauthenticated Information Exposure","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/user-registration\/user-registration-membership-free-paid-memberships-subscriptions-content-restriction-user-profile-custom-user-registration-login-builder-50-527-unauthenticated-information-exposure","description":"The User Registration & Membership \u2013 Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 5.0 through 5.2.7. This makes it possible for unauthenticated attackers to extract sensitive user or configuration data.","date":"2026-09-14"}],"impact":{"cwe":[{"cwe":"CWE-200","name":"Exposure of Sensitive Information to an Unauthorized Actor","description":"The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"4e99fba5b5fd86cefbcd2b59406f4b8941d8778ed430b539f79dcea63ceedae2","name":"User Registration &amp; Membership &#8211; Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder [user-registration] >= 4.4.6 - < 5.2.8","description":null,"operator":{"min_version":"4.4.6","min_operator":"ge","max_version":"5.2.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-86406","name":"CVE-2026-86406","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-86406","description":"[en] The User Registration & Membership  WordPress plugin before 5.2.8 does not check the capability of the user making a membership purchase, and does not validate the payment method or the plan submitted with it, allowing any authenticated user such as a subscriber to be granted the WordPress role attached to a paid plan without paying for it. Where the site owner has mapped a plan to a privileged role, this leads to privilege escalation up to administrator.","date":"2026-09-13"},{"id":"8a4e6ad3a664077afdeb4d29678341a151257b01","name":"User Registration & Membership \u2013 Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder 4.4.6 - 5.2.7 - Authenticated (Subscriber+) Privilege Escalation","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/user-registration\/user-registration-membership-free-paid-memberships-subscriptions-content-restriction-user-profile-custom-user-registration-login-builder-446-527-authenticated-subscriber-privilege-escalation","description":"The User Registration & Membership \u2013 Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to Privilege Escalation in versions 4.4.6 through 5.2.7. This is due to insufficient restriction on the capabilities a user may grant themselves. This makes it possible for authenticated attackers, with subscriber-level access and above, to elevate their privileges beyond those intended for their role.","date":"2026-09-14"}],"impact":{"cwe":[{"cwe":"CWE-269","name":"Improper Privilege Management","description":"The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null}}},{"uuid":"9b149bd533ed4cbf2f0f61286da5036dcbe205f65465e0b5037379ff9d0bb1f6","name":"User Registration &amp; Membership &#8211; Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder [user-registration] < 5.2.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.2.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-80072","name":"CVE-2026-80072","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-80072","description":"[en] The User Registration & Membership  WordPress plugin before 5.2.8 does not validate the destination of a post-login redirect before redirecting, allowing unauthenticated attackers to redirect visitors to an arbitrary external URL, which can be abused for phishing.","date":"2026-09-13"},{"id":"f3e28795d33ad2387d8b15e91818765fc8e85830","name":"User Registration & Membership \u2013 Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder < 5.2.8 - Unauthenticated Open Redirect","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/user-registration\/user-registration-membership-free-paid-memberships-subscriptions-content-restriction-user-profile-custom-user-registration-login-builder-528-unauthenticated-open-redirect","description":"The User Registration & Membership \u2013 Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to Open Redirect in all versions up to 5.2.8 (exclusive). This is due to insufficient validation on the redirect url. This makes it possible for unauthenticated attackers to redirect users to potentially malicious sites if they can successfully trick them into performing an action.","date":"2026-09-14"}],"impact":{"cwe":[{"cwe":"CWE-601","name":"URL Redirection to Untrusted Site ('Open Redirect')","description":"The web application accepts a user-controlled input that specifies a link to an external site, and uses that link in a redirect."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"partial","kev":false,"kev_date":null}}},{"uuid":"54cd4b43c09c01c29e550c67df70757fc35e8ceca5ffec741181609747945edd","name":"User Registration &amp; Membership &#8211; Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder [user-registration] < 5.2.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.2.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-80071","name":"CVE-2026-80071","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-80071","description":"[en] The User Registration & Membership  WordPress plugin before 5.2.8 does not properly restrict who may author a membership plan or validate the plan a user attaches to their own account, allowing authenticated users with Author-level access and above to assign themselves an arbitrary role and escalate their privileges to Administrator.","date":"2026-09-13"},{"id":"EUVD-2026-76952","name":"EUVD-2026-76952","link":"https:\/\/euvd.enisa.europa.eu\/enisa\/EUVD-2026-76952","description":"The User Registration & Membership  WordPress plugin before 5.2.8 does not properly restrict who may author a membership plan or validate the plan a user attaches to their own account, allowing authenticated users with Author-level access and above to assign themselves an arbitrary role and escalate their privileges to Administrator.","date":"2026-09-13"},{"id":"17bdbed5a39d2ef7dbab4a70788201fb250af590","name":"User Registration & Membership \u2013 Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder < 5.2.8 - Authenticated (Author+) Privilege Escalation","link":"https:\/\/www.wordfence.com\/threat-intel\/vulnerabilities\/wordpress-plugins\/user-registration\/user-registration-membership-free-paid-memberships-subscriptions-content-restriction-user-profile-custom-user-registration-login-builder-528-authenticated-author-privilege-escalation","description":"The User Registration & Membership \u2013 Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to 5.2.8. This is due to insufficient restriction on the capabilities a user may grant themselves. This makes it possible for authenticated attackers, with author-level access and above, to elevate their privileges beyond those intended for their role.","date":"2026-09-14"}],"impact":{"cwe":[{"cwe":"CWE-269","name":"Improper Privilege Management","description":"The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor."}],"ssvc":{"exploitation":"none","automatable":"no","technical_impact":"total","kev":false,"kev_date":null},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:H\/UI:N\/S:U\/C:H\/I:H\/A:H","score":"7.2","severity":"high","av":"network","ac":"low","pr":"high","ui":"none","s":"unchanged","c":"high","i":"high","a":"high","exploitable":null,"impact":null}}},{"uuid":"1149ae7c4fb8d3bb0548c6be29c68114f5609e3a83fc7153c1815c43487c0272","name":"User Registration &amp; Membership &#8211; Free &amp; Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration &amp; Login Builder [user-registration] < 5.2.8","description":null,"operator":{"min_version":null,"min_operator":null,"max_version":"5.2.8","max_operator":"lt","unfixed":"0","closed":"0"},"source":[{"id":"CVE-2026-74017","name":"CVE-2026-74017","link":"https:\/\/www.cve.org\/CVERecord?id=CVE-2026-74017","description":"[en] Unauthenticated Broken Access Control in User Registration <= 5.2.7 versions.","date":"2026-09-17"}],"impact":{"cvss":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","av":"n","ac":"l","pr":"n","ui":"n","s":"u","c":"l","i":"n","a":"n","score":"5.3","severity":"m","exploitable":"0.0","impact":"0.0"},"cvss3":{"version":"3.1","vector":"CVSS:3.1\/AV:N\/AC:L\/PR:N\/UI:N\/S:U\/C:L\/I:N\/A:N","score":"5.3","severity":"medium","av":"network","ac":"low","pr":"none","ui":"none","s":"unchanged","c":"low","i":"none","a":"none","exploitable":"0.0","impact":"0.0"},"cwe":[{"cwe":"CWE-862","name":"Missing Authorization","description":"The product does not perform an authorization check when an actor attempts to access a resource or perform an action."}],"ssvc":{"exploitation":"none","automatable":"yes","technical_impact":"partial","kev":false,"kev_date":null}}}]},"updated":"1789709347"}