CVE-2026-6203
- EPSS 1.19%
- Veröffentlicht 13.04.2026 22:25:54
- Zuletzt bearbeitet 13.04.2026 23:16:28
The User Registration & Membership plugin for WordPress is vulnerable to Open Redirect in versions up to and including 5.1.4. This is due to insufficient validation of user-supplied URLs passed via the 'redirect_to_on_logout' GET parameter before red...
CVE-2026-1865
- EPSS 0.03%
- Veröffentlicht 08.04.2026 11:16:56
- Zuletzt bearbeitet 08.04.2026 21:26:13
The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to SQL Injection via the ‘membership_ids[]’ parameter in all v...
CVE-2026-4056
- EPSS 0.02%
- Veröffentlicht 23.03.2026 23:25:49
- Zuletzt bearbeitet 24.03.2026 15:53:48
The User Registration & Membership plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Content Access Rules REST API endpoints in versions 5.0.1 through 5.1.4. This is due to the `check_per...
CVE-2026-1779
- EPSS 0.19%
- Veröffentlicht 26.02.2026 03:16:03
- Zuletzt bearbeitet 15.04.2026 00:35:42
The User Registration & Membership plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.1.2. This is due to incorrect authentication in the 'register_member' function. This makes it possible for unauthentica...
CVE-2025-3281
- EPSS 0.19%
- Veröffentlicht 06.05.2025 07:24:21
- Zuletzt bearbeitet 15.04.2026 00:35:42
The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.2.1 via the create_stripe_subscription() functi...
CVE-2023-27459
- EPSS 0.43%
- Veröffentlicht 26.03.2024 20:15:08
- Zuletzt bearbeitet 14.01.2026 17:00:55
Deserialization of Untrusted Data vulnerability in WPEverest User Registration.This issue affects User Registration: from n/a through 2.3.2.1.