User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder <= 5.2.6 - Missing Authorization
medium
The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 5.2.6. This makes it po...
- CVSS:
- 4.3
- Affected:
- up to 5.2.6
- Fixed in:
- 5.2.7
- Disclosed:
- Aug 14, 2026
CVE-2026-73995 on NVD →
User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder <= 5.2.6 - Missing Authorization
medium
The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 5.2.6. This makes it possib...
- CVSS:
- 5.3
- Affected:
- up to 5.2.6
- Fixed in:
- 5.2.7
- Disclosed:
- Aug 13, 2026
CVE-2026-73403 on NVD →
User Registration & Membership <= 5.2.5 - Missing Authorization to Unauthenticated Account Creation While Registration Disabled
medium
The User Registration & Membership plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 5.2.5. This is due to a missing capability check on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action.
- CVSS:
- 5.3
- Affected:
- up to 5.2.5
- Fixed in:
- 5.2.6
- Disclosed:
- Jul 27, 2026
CVE-2026-16736 on NVD →
User Registration & Membership <= 5.2.2 - Unauthenticated Privilege Escalation
high
The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.2.2. This makes it possible for unauthenticated attackers to registe...
- CVSS:
- 8.1
- Affected:
- up to 5.2.2
- Fixed in:
- 5.2.3
- Disclosed:
- Jun 26, 2026
CVE-2026-11961 on NVD →
User Registration & Membership <= 5.2.2 - Missing Authorization to Unauthenticated User Deletion via Stripe Handler
medium
The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.2.2. This makes it possible for unauthenticated attackers to delete...
- CVSS:
- 5.3
- Affected:
- up to 5.2.2
- Fixed in:
- 5.2.3
- Disclosed:
- Jun 26, 2026
CVE-2026-11966 on NVD →
User Registration & Membership <= 5.2.0 - Missing Authorization to Unauthenticated Payment Bypass
medium
The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to unauthorized modification of data due to missing validation checks in the confirm_payment() function in all versions up to, and i...
- CVSS:
- 6.5
- Affected:
- up to 5.2.0
- Fixed in:
- 5.2.1
- Disclosed:
- Jun 25, 2026
CVE-2026-1869 on NVD →
User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder <= 5.2.2 - Missing Authorization
medium
The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 5.2.2. This makes it possib...
- CVSS:
- 5.3
- Affected:
- up to 5.2.2
- Fixed in:
- 5.2.3
- Disclosed:
- Jun 22, 2026
CVE-2026-52701 on NVD →
User Registration & Membership <= 5.2.1 - Unauthenticated PayPal Bypass to Membership Activation
medium
The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to payment bypass in all versions up to, and including, 5.2.1. This makes it possible for unauthenticated attackers to activate thei...
- CVSS:
- 5.3
- Affected:
- up to 5.2.1
- Fixed in:
- 5.2.2
- Disclosed:
- Jun 22, 2026
CVE-2026-11964 on NVD →
User Registration & Membership <= 5.2.1 - Authenticated (Subscriber+) Insecure Direct Object Reference to Membership Tier Modification
medium
The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.2.1 due to missing validation on a user controlled key....
- CVSS:
- 4.3
- Affected:
- up to 5.2.1
- Fixed in:
- 5.2.2
- Disclosed:
- Jun 22, 2026
CVE-2026-11963 on NVD →
User Registration & Membership <= 5.1.0 - Unauthenticated Payment Bypass
medium
The User Registration & Membership plugin for WordPress is vulnerable to Payment Bypass in versions up to, and including, 5.1.0. This is due to a lack of server-side payment verification. This makes it possible for unauthenticated attackers to bypass payments.
- CVSS:
- 5.3
- Affected:
- up to 5.1.0
- Fixed in:
- 5.2.0
- Disclosed:
- Jun 11, 2026
CVE-2026-11965 on NVD →
User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder <= 5.1.2 - Missing Authorization
medium
The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in versions up to, and including, 5.1.2. This makes it possib...
- CVSS:
- 5.3
- Affected:
- up to 5.1.2
- Fixed in:
- 5.1.3
- Disclosed:
- May 28, 2026
CVE-2026-25425 on NVD →
User Registration & Membership <= 5.1.5 - Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Media Deletion via 'profile-pic-url' Parameter
medium
The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.5. This is due to missing ownership validation on a us...
- CVSS:
- 5.3
- Affected:
- up to 5.1.5
- Fixed in:
- 5.1.6
- Disclosed:
- May 27, 2026
CVE-2026-7651 on NVD →
User Registration & Membership <= 5.1.5 - Unauthenticated Missing Authorization to Admin Approval Bypass via 'action' Parameter
medium
The User Registration & Membership plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 5.1.5. This is due to the is_admin_creation_process() method relying solely on the presence of action=createuser in the $_REQUEST superglobal without performing any authentication or capa...
- CVSS:
- 5.3
- Affected:
- up to 5.1.5
- Fixed in:
- 5.1.6
- Disclosed:
- May 13, 2026
CVE-2026-6145 on NVD →
User Registration & Membership <= 5.1.4 - Missing Authorization to Authenticated (Contributor+) Limited Page Content Modification
medium
The User Registration & Membership plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `embed_form_action()` function in all versions up to, and including, 5.1.4. This makes it possible for authenticated attackers, with Contributor-level access and above, to...
- CVSS:
- 4.3
- Affected:
- up to 5.1.4
- Fixed in:
- 5.1.5
- Disclosed:
- May 4, 2026
CVE-2026-3601 on NVD →
User Registration & Membership <= 5.1.4 - Unauthenticated Open Redirect via 'redirect_to_on_logout' Parameter
medium
The User Registration & Membership plugin for WordPress is vulnerable to Open Redirect in versions up to and including 5.1.4. This is due to insufficient validation of user-supplied URLs passed via the 'redirect_to_on_logout' GET parameter before redirecting users. The `redirect_to_on_logout` GET parameter is passed di...
- CVSS:
- 6.1
- Affected:
- up to 5.1.4
- Fixed in:
- 5.1.5
- Disclosed:
- Apr 13, 2026
CVE-2026-6203 on NVD →
User Registration <= 5.1.5 - Reflected Cross-Site Scripting
medium
The User Registration plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 5.1.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can successful...
- CVSS:
- 6.1
- Affected:
- up to 5.1.5
- Fixed in:
- 5.1.6
- Disclosed:
- Apr 9, 2026
CVE-2026-42652 on NVD →
User Registration & Membership <= 5.1.2 - Authenticated (Subscriber+) SQL Injection via membership_ids[]
medium
The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to SQL Injection via the ‘membership_ids[]’ parameter in all versions up to, and including, 5.1.2 due to insufficient escaping on th...
- CVSS:
- 6.5
- Affected:
- up to 5.1.2
- Fixed in:
- 5.1.3
- Disclosed:
- Apr 7, 2026
CVE-2026-1865 on NVD →
User Registration - Missing Authorization to Authenticated (Contributor+) Content Access Rule Manipulation vulnerability
medium
Missing Authorization to Authenticated (Contributor+) Content Access Rule Manipulation vulnerability
- CVSS:
- 5.4
- Affected:
- up to 5.1.4
- Fixed in:
- 5.1.5
- Disclosed:
- Mar 24, 2026
User Registration & Membership <= 5.1.4 - Missing Authorization to Authenticated (Contributor+) Content Access Rule Manipulation
medium
The User Registration & Membership plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Content Access Rules REST API endpoints in versions 5.0.1 through 5.1.4. This is due to the `check_permissions()` method only checking for `edit_posts` capability instead o...
- CVSS:
- 5.4
- Affected:
- up to 5.1.4
- Fixed in:
- 5.1.5
- Disclosed:
- Mar 23, 2026
CVE-2026-4056 on NVD →
User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder <= 4.4.9 - Unauthenticated Remote Code Execution
critical
The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.4.9. This makes it possible for unauthenticated attackers to execut...
- CVSS:
- 9.8
- Affected:
- up to 4.4.9
- Fixed in:
- 5.1.3
- Disclosed:
- Mar 23, 2026
CVE-2026-32488 on NVD →
User Registration - Unauthenticated Privilege Escalation via Membership Registration vulnerability
critical
Unauthenticated Privilege Escalation via Membership Registration vulnerability
- CVSS:
- 9.8
- Affected:
- up to 5.1.2
- Fixed in:
- 5.1.3
- Disclosed:
- Mar 3, 2026
User Registration & Membership <= 5.1.2 - Unauthenticated Privilege Escalation via Membership Registration
critical
The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to improper privilege management in all versions up to, and including, 5.1.2. This is due to the plugin accepting a user-supplied role during...
- CVSS:
- 9.8
- Affected:
- up to 5.1.2
- Fixed in:
- 5.1.3
- Disclosed:
- Mar 2, 2026
CVE-2026-1492 on NVD →
User Registration & Membership <= 5.1.2 - Insecure Direct Object Reference to Unauthenticated Limited User Deletion
medium
The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.2 via the 'register_member' function, due to missing validation on the 'member_id' user controlled key. This makes...
- CVSS:
- 5.3
- Affected:
- up to 5.1.2
- Fixed in:
- 5.1.3
- Disclosed:
- Feb 25, 2026
CVE-2026-2356 on NVD →
User Registration & Membership <= 5.1.2 - Authentication Bypass
high
The User Registration & Membership plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.1.2. This is due to incorrect authentication in the 'register_member' function. This makes it possible for unauthenticated attackers to log in a newly registered user on the site who has th...
- CVSS:
- 8.1
- Affected:
- up to 5.1.2
- Fixed in:
- 5.1.3
- Disclosed:
- Feb 25, 2026
CVE-2026-1779 on NVD →
User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin [user-registration] <= 4.4.9 (unfixed)
unknown
[en] Missing Authorization vulnerability in wpeverest User Registration user-registration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects User Registration: from n/a through <= 4.4.9.
- Affected:
- up to 4.4.9
- Fix:
- No patched version reported
- Disclosed:
- Jan 22, 2026
CVE-2026-24353 on NVD →
User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin [user-registration] <= 4.4.6 (unfixed)
unknown
[en] Missing Authorization vulnerability in wpeverest User Registration user-registration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects User Registration: from n/a through <= 4.4.6.
- Affected:
- up to 4.4.6
- Fix:
- No patched version reported
- Disclosed:
- Jan 22, 2026
CVE-2025-67956 on NVD →
User Registration <= 4.4.6 - Missing Authorization
medium
The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and including, 4.4.6. This makes it possible fo...
- CVSS:
- 5.3
- Affected:
- up to 4.4.6
- Fixed in:
- 4.4.7
- Disclosed:
- Jan 21, 2026
CVE-2025-67956 on NVD →
User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin [user-registration] < 4.4.9
unknown
[en] The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.4.8. This is due to missing or incorrect nonce validation on the '...
- Affected:
- up to 4.4.9
- Fixed in:
- 4.4.9
- Disclosed:
- Jan 10, 2026
CVE-2025-14976 on NVD →
User Registration & Membership <= 4.4.8 - Cross-Site Request Forgery to Arbitrary Post Deletion
medium
The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.4.8. This is due to missing or incorrect nonce validation on the 'proce...
- CVSS:
- 5.4
- Affected:
- up to 4.4.8
- Fixed in:
- 4.4.9
- Disclosed:
- Jan 9, 2026
CVE-2025-14976 on NVD →
User Registration <= 4.4.9 - Authenticated (Subscriber+) Arbitrary Shortcode Execution
medium
The The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.4.9. This is due to the software allowing users to exec...
- CVSS:
- 5.4
- Affected:
- up to 4.4.9
- Fixed in:
- 5.0
- Disclosed:
- Jan 8, 2026
CVE-2026-24353 on NVD →
User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin <= 4.4.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
medium
The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple shortcode attributes in all versions up to, and including, 4.4.6 due to insufficient input sanitization...
- CVSS:
- 6.4
- Affected:
- up to 4.4.6
- Fixed in:
- 4.4.7
- Disclosed:
- Dec 15, 2025
CVE-2025-13367 on NVD →
User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin [user-registration] < 4.4.7
unknown
[en] The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple shortcode attributes in all versions up to, and including, 4.4.6 due to insufficient input sanitiza...
- Affected:
- up to 4.4.7
- Fixed in:
- 4.4.7
- Disclosed:
- Dec 15, 2025
CVE-2025-13367 on NVD →
User Registration & Membership <= 4.3.0 - Authenticated (Admin+) SQL Injection
medium
The User Registration & Membership plugin for WordPress is vulnerable to SQL Injection via the 's' parameter in version 4.3.0. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with admini...
- CVSS:
- 4.9
- Affected:
- up to 4.3.0
- Fixed in:
- 4.4.0
- Disclosed:
- Sep 5, 2025
CVE-2025-9085 on NVD →
User Registration <= 4.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via urcr_restrict Shortcode
medium
The User Registration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's urcr_restrict shortcode in all versions up to, and including, 4.2.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with co...
- CVSS:
- 6.4
- Affected:
- up to 4.2.4
- Fixed in:
- 4.3.0
- Disclosed:
- Jul 21, 2025
CVE-2025-6831 on NVD →
User Registration & Membership – Custom Registration Form, Login Form, and User Profile <= 4.2.1 - Insecure Direct Object Reference to Unauthenticated Limited User Deletion
medium
The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.2.1 via the create_stripe_subscription() function, due to missing validation on the 'member_id' user controlled key....
- CVSS:
- 5.3
- Affected:
- up to 4.2.1
- Fixed in:
- 4.2.2
- Disclosed:
- May 5, 2025
CVE-2025-3281 on NVD →
User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin [user-registration] < 4.2.0
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpeverest User Registration allows Reflected XSS. This issue affects User Registration: from n/a through n/a.
- Affected:
- up to 4.2.0
- Fixed in:
- 4.2.0
- Disclosed:
- Apr 24, 2025
CVE-2025-39400 on NVD →
User Registration <= 4.1.5 - Reflected Cross-Site Scripting
medium
The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 4.1.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to...
- CVSS:
- 6.1
- Affected:
- up to 4.1.5
- Fixed in:
- 4.2.0
- Disclosed:
- Apr 22, 2025
CVE-2025-39400 on NVD →
User Registration & Membership – Custom Registration Form, Login Form, and User Profile <= 4.1.3 - Insecure Direct Object Reference to Authenticated (Subscriber+) User Password Update
medium
The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.1.3 via the user_registration_update_profile_details() due to missing validation on the 'user_id' user controlled key...
- CVSS:
- 4.3
- Affected:
- up to 4.1.3
- Fixed in:
- 4.1.4
- Disclosed:
- Apr 11, 2025
CVE-2025-3292 on NVD →
User Registration & Membership – Custom Registration Form, Login Form, and User Profile <= 4.1.3 - Insecure Direct Object Reference to Unauthenticated Membership Modification
medium
The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.1.3 via the user_registration_membership_register_member() due to missing validation on the 'membership_id' user cont...
- CVSS:
- 5.3
- Affected:
- up to 4.1.3
- Fixed in:
- 4.1.4
- Disclosed:
- Apr 11, 2025
CVE-2025-3282 on NVD →
User Registration & Membership <= 4.1.2 - Authentication Bypass
high
The User Registration & Membership plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 4.1.2. This is due to incorrect authentication in the 'confirm_payment()' function. This makes it possible for unauthenticated attackers to log in an existing user on the site, even an admini...
- CVSS:
- 8.1
- Affected:
- up to 4.1.2
- Fixed in:
- 4.1.3
- Disclosed:
- Apr 1, 2025
CVE-2025-2594 on NVD →
User Registration <= 4.0.3 - Authenticated (Administrator+) Stored Cross-Site Scripting
medium
The User Registration plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and above, to inject arbitrary web scripts in pa...
- CVSS:
- 4.4
- Affected:
- up to 4.0.3
- Fixed in:
- 4.0.4
- Disclosed:
- Mar 27, 2025
CVE-2025-30899 on NVD →
User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin [user-registration] < 4.0.4
unknown
[en] Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpeverest User Registration allows Stored XSS. This issue affects User Registration: from n/a through 4.0.3.
- Affected:
- up to 4.0.4
- Fixed in:
- 4.0.4
- Disclosed:
- Mar 27, 2025
CVE-2025-30899 on NVD →
User Registration & Membership <= 4.1.1 - Unauthenticated Privilege Escalation
critical
The User Registration & Membership plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 4.1.1. This is due to insufficient restrictions on role type in the 'prepare_members_data()' function. This makes it possible for unauthenticated attackers to create new user accounts with the...
- CVSS:
- 9.8
- Affected:
- up to 4.1.1
- Fixed in:
- 4.1.2
- Disclosed:
- Mar 24, 2025
CVE-2025-2563 on NVD →
User Registration & Membership – Custom Registration Form, Login Form, and User Profile <= 4.0.4 - Reflected Cross-Site Scripting
medium
The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 4.0.4 due to insufficient input sanitization and output escaping. This makes it possible for unauth...
- CVSS:
- 6.1
- Affected:
- up to 4.0.4
- Fixed in:
- 4.1.0
- Disclosed:
- Feb 27, 2025
CVE-2025-1511 on NVD →
User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin [user-registration] < 2.3.3
unknown
[en] Missing Authorization vulnerability in WPEverest User Registration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects User Registration: from n/a through 2.3.2.1.
- Affected:
- up to 2.3.3
- Fixed in:
- 2.3.3
- Disclosed:
- Dec 9, 2024
CVE-2023-29429 on NVD →
User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin [user-registration] < 3.2.1
unknown
[en] The User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'import_form_action' function in versions up to, and including, 3.2.0.1. This makes it possible for authen...
- Affected:
- up to 3.2.1
- Fixed in:
- 3.2.1
- Disclosed:
- Jun 1, 2024
CVE-2024-4958 on NVD →
User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin <= 3.2.0.1 - Missing Authorization to Privilege Escalation
high
The User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'import_form_action' function in versions up to, and including, 3.2.0.1. This makes it possible for authenticat...
- CVSS:
- 7.1
- Affected:
- up to 3.2.0.1
- Fixed in:
- 3.2.1
- Disclosed:
- May 31, 2024
CVE-2024-4958 on NVD →
User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin [user-registration] < 3.2.0
unknown
[en] The User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the profile_pic_remove function in versions up to, and including, 3.1.5. This makes it possible for unauthenticated at...
- Affected:
- up to 3.2.0
- Fixed in:
- 3.2.0
- Disclosed:
- May 2, 2024
CVE-2024-3295 on NVD →
User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin [user-registration] < 3.2.0
unknown
[en] The User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the form_save_action() function in all versions up to, and including, 3.1.5. This makes it possible for authenticated attac...
- Affected:
- up to 3.2.0
- Fixed in:
- 3.2.0
- Disclosed:
- May 2, 2024
CVE-2024-2417 on NVD →
User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin <= 3.1.5 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation
high
The User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the form_save_action() function in all versions up to, and including, 3.1.5. This makes it possible for authenticated attackers,...
- CVSS:
- 8.8
- Affected:
- up to 3.1.5
- Fixed in:
- 3.2.0
- Disclosed:
- Apr 19, 2024
CVE-2024-2417 on NVD →
User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin <= 3.1.5 - Missing Authorization to Unauthenticated Media Deletion
medium
The User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the profile_pic_remove function in versions up to, and including, 3.1.5. This makes it possible for unauthenticated attacke...
- CVSS:
- 6.5
- Affected:
- up to 3.1.5
- Fixed in:
- 3.2.0
- Disclosed:
- Apr 15, 2024
CVE-2024-3295 on NVD →
User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin [user-registration] < 2.3.3
unknown
[en] Deserialization of Untrusted Data vulnerability in WPEverest User Registration.This issue affects User Registration: from n/a through 2.3.2.1.
- Affected:
- up to 2.3.3
- Fixed in:
- 2.3.3
- Disclosed:
- Mar 26, 2024
CVE-2023-27459 on NVD →
User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin [user-registration] < 3.1.5
unknown
[en] The User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Display Name' parameter in all versions up to, and including, 3.1.4 due to insufficient input sanitization and output escaping. This makes it po...
- Affected:
- up to 3.1.5
- Fixed in:
- 3.1.5
- Disclosed:
- Mar 7, 2024
CVE-2024-1720 on NVD →
User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin <= 3.1.4 - Unauthenticated Stored Self-Based Cross-Site Scripting
medium
The User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Display Name' parameter in all versions up to, and including, 3.1.4 due to insufficient input sanitization and output escaping. This makes it possibl...
- CVSS:
- 4.7
- Affected:
- up to 3.1.4
- Fixed in:
- 3.1.5
- Disclosed:
- Mar 6, 2024
CVE-2024-1720 on NVD →
User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin [user-registration] < 3.0.4.2
unknown
[en] The User Registration WordPress plugin before 3.0.4.2 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).
- Affected:
- up to 3.0.4.2
- Fixed in:
- 3.0.4.2
- Disclosed:
- Nov 6, 2023
CVE-2023-5228 on NVD →
User Registration – Custom Registration Form, Login Form And User Profile For WordPress <= 3.0.4.1 - Authenticated (Admin+) Stored Cross-Site Scripting
medium
The User Registration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.0.4.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inje...
- CVSS:
- 4.4
- Affected:
- up to 3.0.4.1
- Fixed in:
- 3.0.4.2
- Disclosed:
- Oct 16, 2023
CVE-2023-5228 on NVD →
User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin [user-registration] < 3.0.2.1
unknown
[en] The User Registration plugin for WordPress is vulnerable to arbitrary file uploads due to a hardcoded encryption key and missing file type validation on the 'ur_upload_profile_pic' function in versions up to, and including, 3.0.2. This makes it possible for authenticated attackers with subscriber-level capabilitie...
- Affected:
- up to 3.0.2.1
- Fixed in:
- 3.0.2.1
- Disclosed:
- Jul 13, 2023
CVE-2023-3342 on NVD →
User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin [user-registration] < 3.0.2
unknown
[en] The User Registration plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.0.1 via deserialization of untrusted input from the 'profile-pic-url' parameter. This allows authenticated attackers, with subscriber-level permissions and above, to inject a PHP Object. No POP chai...
- Affected:
- up to 3.0.2
- Fixed in:
- 3.0.2
- Disclosed:
- Jul 13, 2023
CVE-2023-3343 on NVD →
User Registration <= 3.0.2 - Authenticated (Subscriber+) Arbitrary File Upload
critical
The User Registration plugin for WordPress is vulnerable to arbitrary file uploads due to a hardcoded encryption key and missing file type validation on the 'ur_upload_profile_pic' function in versions up to, and including, 3.0.2. This makes it possible for authenticated attackers with subscriber-level capabilities or...
- CVSS:
- 9.9
- Affected:
- up to 3.0.2
- Fixed in:
- 3.0.2.1
- Disclosed:
- Jul 4, 2023
CVE-2023-3342 on NVD →
User Registration <= 3.0.1 - Authenticated (Subscriber+) PHP Object Injection
high
The User Registration plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.0.1 via deserialization of untrusted input from the 'profile-pic-url' parameter. This allows authenticated attackers, with subscriber-level permissions and above, to inject a PHP Object. No POP chain is...
- CVSS:
- 8.8
- Affected:
- up to 3.0.1
- Fixed in:
- 3.0.2
- Disclosed:
- Jun 29, 2023
CVE-2023-3343 on NVD →
User Registration <= 2.3.2.1 - Missing Authorization via send_test_email
medium
The User Registration plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the send_test_email function in versions up to, and including, 2.3.2.1. This makes it possible for unauthenticated attackers to send a test email.
- CVSS:
- 5.3
- Affected:
- up to 2.3.2.1
- Fixed in:
- 2.3.3
- Disclosed:
- Apr 6, 2023
CVE-2023-29429 on NVD →
User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin [user-registration] < 2.3.3
unknown
[en] Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPEverest User Registration plugin <= 2.3.0 versions.
- Affected:
- up to 2.3.3
- Fixed in:
- 2.3.3
- Disclosed:
- Apr 6, 2023
CVE-2023-23987 on NVD →
User Registration <= 2.3.2.1 - PHP Object Injection
high
The User Registration plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 2.3.2.1 via deserialization of untrusted input in the following functions: ur_get_user_extra_fields, user_registration_form_field. This allows subscriber-level attackers to inject a PHP Object. No POP cha...
- CVSS:
- 7.5
- Affected:
- up to 2.3.2.1
- Fixed in:
- 2.3.3
- Disclosed:
- Mar 21, 2023
CVE-2023-27459 on NVD →
User Registration <= 2.3.0 - Authenticated (Administrator+) Stored Cross Site Scripting
medium
The User Registration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via field settings in versions up to, and including, 2.3.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrative-level permissions and above, to inject ar...
- CVSS:
- 5.5
- Affected:
- up to 2.3.0
- Fixed in:
- 2.3.1
- Disclosed:
- Jan 20, 2023
CVE-2023-23987 on NVD →
User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin [user-registration] < 2.2.4.1
unknown
[en] The User Registration WordPress plugin before 2.2.4.1 does not properly restrict the files to be uploaded via an AJAX action available to both unauthenticated and authenticated users, which could allow unauthenticated users to upload PHP files for example.
- Affected:
- up to 2.2.4.1
- Fixed in:
- 2.2.4.1
- Disclosed:
- Dec 12, 2022
CVE-2022-3912 on NVD →
User Registration <= 2.2.4 - Authenticated (Subscriber+) Arbitrary File Upload
high
The User Registration plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation via the profile_pic_upload function in versions up to, and including, 2.2.4. This makes it possible for authenticated attackers, with subscriber access or higher, to upload arbitrary files on the affec...
- CVSS:
- 8.8
- Affected:
- up to 2.2.4
- Fixed in:
- 2.2.41
- Disclosed:
- Nov 21, 2022
CVE-2022-3912 on NVD →
User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin [user-registration] < 2.0.2
unknown
[en] The User Registration WordPress plugin before 2.0.2 does not properly sanitise the user_registration_profile_pic_url value when submitted directly via the user_registration_update_profile_details AJAX action. This could allow any authenticated user, such as subscriber, to perform Stored Cross-Site attacks when the...
- Affected:
- up to 2.0.2
- Fixed in:
- 2.0.2
- Disclosed:
- Oct 4, 2021
CVE-2021-24654 on NVD →
User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin [user-registration] < 1.5.6
unknown
Authenticated Cross-Site Scripting (XSS) vulnerability found by "Mr Winst0n" in WordPress User Registration plugin (versions <= 1.5.5).
- Affected:
- up to 1.5.6
- Fixed in:
- 1.5.6
- Disclosed:
- Jan 14, 2019
User Registration <= 1.5.5 - Cross-Site Scripting
medium
The User Registration plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.5.5 due to insufficient input sanitization and output escaping via the 'edit-registration' parameter. This makes it possible for authenticated attackers to inject arbitrary web scripts that execute in a...
- CVSS:
- 6.4
- Affected:
- up to 1.5.5
- Fixed in:
- 1.5.6
- Disclosed:
- Jan 9, 2019
User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin [user-registration] < 1.5.6
unknown
The User Registration plugin for WordPress is vulnerable to Cross-Site Scripting in versions up to, and including, 1.5.5 due to insufficient input sanitization and output escaping via the 'edit-registration' parameter. This makes it possible for authenticated attackers to inject arbitrary web scripts that execute in a...
- Affected:
- up to 1.5.6
- Fixed in:
- 1.5.6
- Disclosed:
- Jan 9, 2019
User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin [user-registration] < 4.1.0
unknown
- Affected:
- up to 4.1.0
- Fixed in:
- 4.1.0
CVE-2025-1511 on NVD →
User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin [user-registration] < 4.3.0
unknown
- Affected:
- up to 4.3.0
- Fixed in:
- 4.3.0
CVE-2025-6831 on NVD →
User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin [user-registration] < 1.5.6
unknown
The User Registration – Custom Registration Form, Login And User Profile For WordPress WordPress plugin was affected by an Authenticated Cross-Site Scripting (XSS) security vulnerability.
- Affected:
- up to 1.5.6
- Fixed in:
- 1.5.6
User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin [user-registration] < 4.1.2
unknown
- Affected:
- up to 4.1.2
- Fixed in:
- 4.1.2
CVE-2025-2563 on NVD →
User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin [user-registration] < 4.1.3
unknown
- Affected:
- up to 4.1.3
- Fixed in:
- 4.1.3
CVE-2025-2594 on NVD →
User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin [user-registration] < 4.1.4
unknown
- Affected:
- up to 4.1.4
- Fixed in:
- 4.1.4
CVE-2025-3292 on NVD →
User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin [user-registration] < 4.1.4
unknown
- Affected:
- up to 4.1.4
- Fixed in:
- 4.1.4
CVE-2025-3282 on NVD →
User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin [user-registration] < 4.2.2
unknown
- Affected:
- up to 4.2.2
- Fixed in:
- 4.2.2
CVE-2025-3281 on NVD →