CVE-2025-2594

The User Registration & Membership WordPress plugin before 4.1.3 does not properly validate data in an AJAX action when the Membership Addon is enabled, allowing attackers to authenticate as any user, including administrators, by simply using the target account's user ID.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:wpeverest:user_registration_\&_membership:*:*:*:*:free:wordpress:*:*
cpe:2.3:a:wpeverest:user_registration_\&_membership:*:*:*:*:pro:wordpress:*:*

History

07 May 2025, 19:27

Type Values Removed Values Added
First Time Wpeverest user Registration \& Membership
Wpeverest
CWE NVD-CWE-noinfo
CPE cpe:2.3:a:wpeverest:user_registration_\&_membership:*:*:*:*:free:wordpress:*:*
cpe:2.3:a:wpeverest:user_registration_\&_membership:*:*:*:*:pro:wordpress:*:*
References () https://wpscan.com/vulnerability/1c1be47a-d5c0-4ac1-b9fd-475b382a7d8f/ - () https://wpscan.com/vulnerability/1c1be47a-d5c0-4ac1-b9fd-475b382a7d8f/ - Exploit, Third Party Advisory

22 Apr 2025, 15:16

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 8.1
Summary
  • (es) El complemento User Registration & Membership de WordPress anterior a la versión 4.1.3 no valida correctamente los datos en una acción AJAX cuando el complemento de membresía está habilitado, lo que permite a los atacantes autenticarse como cualquier usuario, incluidos los administradores, simplemente usando el ID de usuario de la cuenta de destino.

22 Apr 2025, 06:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-04-22 06:15

Updated : 2025-05-07 19:27


NVD link : CVE-2025-2594

Mitre link : CVE-2025-2594

CVE.ORG link : CVE-2025-2594


JSON object : View

Products Affected

wpeverest

  • user_registration_\&_membership