CVE-2025-1511
- EPSS 0.31%
- Veröffentlicht 28.02.2025 06:15:25
- Zuletzt bearbeitet 06.03.2025 17:52:55
The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 4.0.4 due to insufficient inp...
CVE-2023-29429
- EPSS 0.4%
- Veröffentlicht 09.12.2024 13:15:27
- Zuletzt bearbeitet 28.04.2026 19:20:13
Missing Authorization vulnerability in WPEverest User Registration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects User Registration: from n/a through 2.3.2.1.
CVE-2024-4958
- EPSS 0.33%
- Veröffentlicht 01.06.2024 08:15:08
- Zuletzt bearbeitet 15.04.2026 00:35:42
The User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'import_form_action' function in versions...
CVE-2024-3295
- EPSS 0.91%
- Veröffentlicht 02.05.2024 17:15:24
- Zuletzt bearbeitet 15.04.2026 00:35:42
The User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the profile_pic_remove function in versions up to, an...
CVE-2024-2417
- EPSS 0.94%
- Veröffentlicht 02.05.2024 17:15:17
- Zuletzt bearbeitet 15.04.2026 00:35:42
The User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the form_save_action() function in all versions up to, and...
CVE-2023-27459
- EPSS 0.61%
- Veröffentlicht 26.03.2024 20:15:08
- Zuletzt bearbeitet 28.04.2026 19:20:02
Deserialization of Untrusted Data vulnerability in WPEverest User Registration.This issue affects User Registration: from n/a through 2.3.2.1.
CVE-2023-5228
- EPSS 0.56%
- Veröffentlicht 06.11.2023 21:15:09
- Zuletzt bearbeitet 26.02.2025 22:15:13
The User Registration WordPress plugin before 3.0.4.2 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is d...
CVE-2023-3343
- EPSS 1.13%
- Veröffentlicht 13.07.2023 03:15:10
- Zuletzt bearbeitet 08.04.2026 18:18:09
The User Registration plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.0.1 via deserialization of untrusted input from the 'profile-pic-url' parameter. This allows authenticated attackers, with subscriber...
CVE-2023-3342
- EPSS 1.69%
- Veröffentlicht 13.07.2023 03:15:10
- Zuletzt bearbeitet 08.04.2026 19:18:24
The User Registration plugin for WordPress is vulnerable to arbitrary file uploads due to a hardcoded encryption key and missing file type validation on the 'ur_upload_profile_pic' function in versions up to, and including, 3.0.2. This makes it possi...
CVE-2023-23987
- EPSS 0.39%
- Veröffentlicht 06.04.2023 06:15:09
- Zuletzt bearbeitet 28.04.2026 19:19:36
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPEverest User Registration plugin <= 2.3.0 versions.