Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-3282


The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.1.3 via the user_registration_membership_register_member() due to missing validation on the 'membership_id' user controlled key. This makes it possible for unauthenticated attackers to update any user's membership to any other active or non-active membership type.


Published

2025-04-12T07:15:27.003

Last Modified

2025-07-08T18:32:17.517

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 5.3 (MEDIUM)

Weaknesses
  • Type: Secondary
    CWE-639

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application wpeverest user_registration_\&_membership < 4.1.4 Yes

References