CVE-2025-2563 is a critical privilege escalation vulnerability affecting the WordPress User Registration & Membership plugin versions prior to 4.1.2. When the Membership Addon is enabled, unauthenticated users can exploit this flaw to set their account role, gaining administrative privileges. This vulnerability has a CVSS score of 8.1 (HIGH) due to its unauthenticated nature, low attack complexity, and high impact on confidentiality, integrity, and availability. Exploit code is publicly available via Metasploit and Nuclei templates, and it has garnered significant community discussion, indicating a high likelihood of active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 4.1.2CPE matchmatch criteria | cpe:2.3:a:wpeverest:user_registration_\&_membership:*:*:*:*:free:wordpress:*:* | ||
< 5.1.2CPE matchmatch criteria | cpe:2.3:a:wpeverest:user_registration_\&_membership:*:*:*:*:pro:wordpress:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.