CVE-2025-2563: User Registration & Membership < 4.1.2- Unauthenticated Privilege Escalation
The User Registration & Membership WordPress plugin before 4.1.2 does not prevent users to set their account role when the Membership Addon is enabled, leading to a privilege escalation issue and allowing unauthenticated users to gain admin privileges
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2563?
CVE-2025-2563 has a high severity rating due to its potential for privilege escalation.
How do I fix CVE-2025-2563?
To mitigate CVE-2025-2563, update the User Registration & Membership plugin to version 4.1.2 or later.
What systems are impacted by CVE-2025-2563?
CVE-2025-2563 affects the User Registration & Membership plugin for WordPress versions before 4.1.2.
What vulnerabilities does CVE-2025-2563 introduce?
CVE-2025-2563 allows unauthenticated users to set their account role, potentially granting them admin privileges.
Is there a workaround for CVE-2025-2563 prior to updating?
A temporary workaround for CVE-2025-2563 is to disable the Membership Addon until the plugin is updated.