Back to search
CVE-2025-2594
Published: Apr 22, 2025
Modified: Aug 27, 2025
PUBLISHED
Description
The User Registration & Membership WordPress plugin before 4.1.3 does not properly validate data in an AJAX action when the Membership Addon is enabled, allowing attackers to authenticate as any user, including administrators, by simply using the target account's user ID.
| Vendor | Product | Versions |
|---|---|---|
Unknown | User Registration & Membership | affected 0 - < 4.1.3 |
References
https://wpscan.com/vulnerability/1c1be47a-d5c0-4ac1-b9fd-475b382a7d8f/
exploit
vdb-entry
technical-description
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now