CVE-2025-2563
14.04.2025, 06:15
The User Registration & Membership WordPress plugin before 4.1.2 does not prevent users to set their account role when the Membership Addon is enabled, leading to a privilege escalation issue and allowing unauthenticated users to gain admin privilegesEnginsight
Vendor | Product | Version |
---|---|---|
wpeverest | user_registration_\&_membership | 𝑥 < 4.1.2 |
wpeverest | user_registration_\&_membership | 𝑥 < 5.1.2 |
𝑥
= Vulnerable software versions