CVE Database
/

CVE-2025-2594

Back to search

CVE-2025-2594

Published: Apr 22, 2025

Modified: Aug 27, 2025

PUBLISHED

Description

The User Registration & Membership WordPress plugin before 4.1.3 does not properly validate data in an AJAX action when the Membership Addon is enabled, allowing attackers to authenticate as any user, including administrators, by simply using the target account's user ID.

VendorProductVersions

Unknown

User Registration & Membership

affected
0 - < 4.1.3

References

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now