WordPress Plugin Vulnerabilities

User Registration & Membership (Free < 4.1.3, Pro < 5.1.3) - Authentication Bypass

Description

The plugins do not properly validate data in an AJAX action when the Membership Addon is enabled, allowing attackers to authenticate as any user, including administrators, by simply using the target account's user ID.

Proof of Concept

Affects Plugins

Fixed in 4.1.3

References

Classification

Type
IDOR
CWE
CVSS

Miscellaneous

Original Researcher
wesley (wcraft)
Submitter
wesley (wcraft)
Verified
Yes

Timeline

Publicly Published
2025-04-01 (about 9 months ago)
Added
2025-04-01 (about 9 months ago)
Last Updated
2025-08-26 (about 4 months ago)

Other