CVE-2025-2563
PoC largeUnauthenticated Privilege Escalation in WPEverest User Registration & Membership
The User Registration & Membership WordPress plugin by WPEverest, prior to version 4.1.2, fails to prevent users from selecting their own account role during registration when the Membership Addon is enabled. An unauthenticated attacker can submit a registration with the role set to administrator and thereby gain full admin control of the affected WordPress site. The flaw is rated 8.1 (high) with network reachability, no privileges or user interaction required, and high attack complexity because it only triggers under the specific Membership Addon configuration. Any WordPress site running User Registration & Membership before 4.1.2 with the Membership Addon enabled and self-registration open is affected. No confirmed in-the-wild exploitation is reported and it is not in CISA KEV, but a public proof of concept exists and EPSS assigns a roughly 46% probability of exploitation within 30 days (99th percentile).
What to do: Upgrade User Registration & Membership to version 4.1.2 or later immediately; as a stopgap, disable the Membership Addon or close self-registration to remove the attack path. After patching, audit the user list for recently created administrator accounts you did not create, since successful exploitation may have gone unnoticed.
| wpeverest User Registration & Membership | all versions before 4.1.2 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The User Registration & Membership WordPress plugin before 4.1.2 does not prevent users to set their account role when the Membership Addon is enabled, leading to a privilege escalation issue and allowing unauthenticated users to gain admin privileges
- Vendors
- wpeverest
- Products
- user registration \& membership
- Ecosystems
- WordPress
- Vector
- CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.