WordPress Plugin Vulnerabilities

User Registration & Membership (Free < 4.1.2, Pro < 5.1.2) - Unauthenticated Privilege Escalation

Description

The plugins do not prevent users to set their account role when the Membership Addon is enabled, leading to a privilege escalation issue and allowing unauthenticated users to gain admin privileges

Proof of Concept

Affects Plugins

Fixed in 4.1.2

References

Classification

Type
IDOR
CWE
CVSS

Miscellaneous

Original Researcher
wesley (wcraft)
Submitter
wesley (wcraft)
Verified
Yes

Timeline

Publicly Published
2025-03-24 (about 9 months ago)
Added
2025-03-24 (about 9 months ago)
Last Updated
2025-08-26 (about 4 months ago)

Other