PT-2025-16167 · WordPress · User Registration & Membership

·

CVE-2025-3282

·

Published

2025-04-12

·

Updated

2025-07-08

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions: User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress versions up to, and including, 4.1.3
Description: The issue allows unauthenticated attackers to update any user's membership to any other active or non-active membership type due to missing validation on the membership id user-controlled key in the user registration membership register member() function. This is a result of Insecure Direct Object Reference.
Recommendations: For versions up to, and including, 4.1.3, consider disabling the user registration membership register member() function until a patch is available to prevent exploitation. Restrict access to the membership id key to minimize the risk of unauthorized membership updates.

Fix

IDOR

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-3282

Affected Products

User Registration & Membership