Return to CVE list

CVE-2025-2563

8.1
Critical

CVE-2025-2563

contact@wpscan.com
Analyzed

Description

The User Registration & Membership WordPress plugin before 4.1.2 does not prevent users to set their account role when the Membership Addon is enabled, leading to a privilege escalation issue and allowing unauthenticated users to gain admin privileges

Exploits

No known exploits found for this CVE.

Search Exploit-DB