ZeroHour

CVE-2025-2563

PoC large

Unauthenticated Privilege Escalation in WPEverest User Registration & Membership

CVSS 3.1
8.1 high
EPSS
49%p99
Published
()
Modified
AI analysis

The User Registration & Membership WordPress plugin by WPEverest, prior to version 4.1.2, fails to prevent users from selecting their own account role during registration when the Membership Addon is enabled. An unauthenticated attacker can submit a registration with the role set to administrator and thereby gain full admin control of the affected WordPress site. The flaw is rated 8.1 (high) with network reachability, no privileges or user interaction required, and high attack complexity because it only triggers under the specific Membership Addon configuration. Any WordPress site running User Registration & Membership before 4.1.2 with the Membership Addon enabled and self-registration open is affected. No confirmed in-the-wild exploitation is reported and it is not in CISA KEV, but a public proof of concept exists and EPSS assigns a roughly 46% probability of exploitation within 30 days (99th percentile).

What to do: Upgrade User Registration & Membership to version 4.1.2 or later immediately; as a stopgap, disable the Membership Addon or close self-registration to remove the attack path. After patching, audit the user list for recently created administrator accounts you did not create, since successful exploitation may have gone unnoticed.

Affected
wpeverest User Registration & Membershipall versions before 4.1.2
Estimated exposure
large≈100,000+ WordPress sites (plugin has roughly 100k active installs) — WordPress.org lists the User Registration plugin at roughly 100,000+ active installs, with the actually vulnerable subset narrowed to sites that enable the Membership Addon with open user registration.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The User Registration & Membership WordPress plugin before 4.1.2 does not prevent users to set their account role when the Membership Addon is enabled, leading to a privilege escalation issue and allowing unauthenticated users to gain admin privileges

Vendors
wpeverest
Products
user registration \& membership
Ecosystems
WordPress
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.