CVE-2025-2594: User Registration & Membership < 4.1.3 - Authentication Bypass
The User Registration & Membership WordPress plugin before 4.1.3 does not properly validate data in an AJAX action when the Membership Addon is enabled, allowing attackers to authenticate as any user, including administrators, by simply using the target account's user ID.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-2594?
CVE-2025-2594 is classified as a critical vulnerability due to its potential to allow unauthorized access to user accounts.
How do I fix CVE-2025-2594?
To fix CVE-2025-2594, update the User Registration & Membership WordPress plugin to version 4.1.3 or higher.
What does CVE-2025-2594 affect?
CVE-2025-2594 affects the User Registration & Membership plugin for WordPress versions prior to 4.1.3.
How does CVE-2025-2594 exploit user authentication?
CVE-2025-2594 exploits a failure to properly validate data in an AJAX action, allowing attackers to authenticate as any user by utilizing the user ID.
Who is at risk with CVE-2025-2594?
Anyone using the affected versions of the User Registration & Membership WordPress plugin is at risk, especially sites with registered users.