PT-2025-16167 · WordPress · User Registration & Membership
Wesley
·
Published
2025-04-12
·
Updated
2025-07-08
·
CVE-2025-3282
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions:
User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress versions up to, and including, 4.1.3
Description:
The issue allows unauthenticated attackers to update any user's membership to any other active or non-active membership type due to missing validation on the
membership id user-controlled key in the user registration membership register member() function. This is a result of Insecure Direct Object Reference.Recommendations:
For versions up to, and including, 4.1.3, consider disabling the
user registration membership register member() function until a patch is available to prevent exploitation. Restrict access to the membership id key to minimize the risk of unauthorized membership updates.Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
User Registration & Membership