PT-2025-16167 · WordPress · User Registration & Membership

Wesley

·

Published

2025-04-12

·

Updated

2025-07-08

·

CVE-2025-3282

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions: User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress versions up to, and including, 4.1.3
Description: The issue allows unauthenticated attackers to update any user's membership to any other active or non-active membership type due to missing validation on the membership id user-controlled key in the user registration membership register member() function. This is a result of Insecure Direct Object Reference.
Recommendations: For versions up to, and including, 4.1.3, consider disabling the user registration membership register member() function until a patch is available to prevent exploitation. Restrict access to the membership id key to minimize the risk of unauthorized membership updates.

Fix

IDOR

Weakness Enumeration

Related Identifiers

CVE-2025-3282

Affected Products

User Registration & Membership