First published: Mon Apr 14 2025(Updated: )
The User Registration & Membership WordPress plugin before 4.1.2 does not prevent users to set their account role when the Membership Addon is enabled, leading to a privilege escalation issue and allowing unauthenticated users to gain admin privileges
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress User Registration Forms | <4.1.2 | |
WPEverest User Registration & Membership WordPress | <4.1.2 | |
WPEverest User Registration & Membership WordPress | <5.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-2563 has a high severity rating due to its potential for privilege escalation.
To mitigate CVE-2025-2563, update the User Registration & Membership plugin to version 4.1.2 or later.
CVE-2025-2563 affects the User Registration & Membership plugin for WordPress versions before 4.1.2.
CVE-2025-2563 allows unauthenticated users to set their account role, potentially granting them admin privileges.
A temporary workaround for CVE-2025-2563 is to disable the Membership Addon until the plugin is updated.