PT-2025-47713 · WordPress · Simple User Registration

Athiwat Tiprasaharn

·

Published

2025-11-21

·

Updated

2025-11-26

·

CVE-2025-12160

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions Simple User Registration versions up to and including 6.6
Description The Simple User Registration plugin for WordPress is susceptible to Stored Cross-Site Scripting. This is due to insufficient input sanitization and output escaping in the wpr admin msg parameter. This allows unauthenticated attackers to inject arbitrary web scripts into pages, which will execute when a user accesses the injected page.
Recommendations Update Simple User Registration to a version newer than 6.6.

Fix

XSS

Weakness Enumeration

Related Identifiers

CVE-2025-12160

Affected Products

Simple User Registration