First published: Tue Apr 22 2025(Updated: )
The User Registration & Membership WordPress plugin before 4.1.3 does not properly validate data in an AJAX action when the Membership Addon is enabled, allowing attackers to authenticate as any user, including administrators, by simply using the target account's user ID.
Credit: contact@wpscan.com
Affected Software | Affected Version | How to fix |
---|---|---|
WordPress User Registration & Membership plugin | <4.1.3 | |
WPEverest User Registration & Membership WordPress | <4.1.3 | |
WPEverest User Registration & Membership WordPress | <5.1.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-2594 is classified as a critical vulnerability due to its potential to allow unauthorized access to user accounts.
To fix CVE-2025-2594, update the User Registration & Membership WordPress plugin to version 4.1.3 or higher.
CVE-2025-2594 affects the User Registration & Membership plugin for WordPress versions prior to 4.1.3.
CVE-2025-2594 exploits a failure to properly validate data in an AJAX action, allowing attackers to authenticate as any user by utilizing the user ID.
Anyone using the affected versions of the User Registration & Membership WordPress plugin is at risk, especially sites with registered users.