User Registration
Vendor:
First CVE: Oct 4, 2021 · Active for 4 years
14
Total CVEs
More Total CVEs than 92% of tracked products
2.3
Avg CVEs / Year
Higher CVE frequency than 76% of tracked products
6.8
Avg CVSS
Higher Avg CVSS than 42% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact User Registration over time
Volume of CVEsAvg CVSS Base Score
First CVE
Oct 4, 2021
4 years ago
Most Recent CVE
Apr 29, 2026
90 days ago
CVE Severity & Scoring
User Registration14 CVEs
50%
43%
All CVEs353,173 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network14 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low14 (100.0%)
High0 (0.0%)
Unknown0 (0.0%)
User Interaction
None7 (50.0%)
Unknown0 (0.0%)
Required7 (50.0%)
Privileges Required
Low5 (35.7%)
High3 (21.4%)
None6 (42.9%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (14 CVEs).
14 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-24353HIGH Missing Authorization vulnerability in wpeverest User Registration user-registration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects User | Jan 22, 2026 | 8.1 | 29 | NO | NO |
CVE-2025-67956HIGH Missing Authorization vulnerability in wpeverest User Registration user-registration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects User | Jan 22, 2026 | 8.2 | 29 | NO | NO |
CVE-2023-3342CRITICAL The User Registration plugin for WordPress is vulnerable to arbitrary file uploads due to a hardcoded encryption key and missing file type validation on the 'ur_upload_profile_pic' | Jul 13, 2023 | 9.9 | 28 | NO | NO |
CVE-2026-42652HIGH Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpeverest User Registration user-registration allows Reflected XSS.This issue | Apr 29, 2026 | 7.1 | 26 | NO | NO |
CVE-2023-3343HIGH The User Registration plugin for WordPress is vulnerable to PHP Object Injection in versions up to, and including, 3.0.1 via deserialization of untrusted input from the 'profile-pi | Jul 13, 2023 | 8.8 | 26 | NO | NO |
CVE-2023-27459HIGH Deserialization of Untrusted Data vulnerability in WPEverest User Registration.This issue affects User Registration: from n/a through 2.3.2.1. | Mar 26, 2024 | 8.8 | 24 | NO | NO |
CVE-2022-3912HIGH The User Registration WordPress plugin before 2.2.4.1 does not properly restrict the files to be uploaded via an AJAX action available to both unauthenticated and authenticated use | Dec 12, 2022 | 7.5 | 24 | NO | NO |
CVE-2025-1511MEDIUM The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' paramet | Feb 28, 2025 | 6.1 | 20 | NO | NO |
CVE-2021-24654MEDIUM The User Registration WordPress plugin before 2.0.2 does not properly sanitise the user_registration_profile_pic_url value when submitted directly via the user_registration_update_ | Oct 4, 2021 | 5.4 | 20 | NO | NO |
CVE-2023-23987MEDIUM Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPEverest User Registration plugin <= 2.3.0 versions. | Apr 6, 2023 | 4.8 | 19 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (14 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (14 CVEs).
Media Mentions
Signals from CVEs in this product scope (14 CVEs).
Top CNAs Publishing CVEs For User Registration
Top CWEs
Versions
No cataloged versions.