User Registration and Membership WordPress Plugin Cross-Site Request Forgery Vulnerability Allowing Arbitrary Post Deletion

Vulnerability

A Cross-Site Request Forgery (CSRF) vulnerability has been identified in the User Registration & Membership WordPress plugin, specifically in versions through 4.4.8. The issue arises from inadequate nonce validation in the 'process_row_actions' function when the 'delete' action is invoked. This vulnerability enables unauthenticated attackers to delete arbitrary posts by sending a forged request, provided they can persuade a site administrator to click a link or perform a similar action.

Impact

Exploitation of this vulnerability allows for the unauthorized deletion of posts.

Reproduction

To reproduce this vulnerability, an attacker must send a forged request to a WordPress site using the vulnerable plugin version. This request should include the 'delete' action for a specific post. The attacker must also trick an administrator into clicking a link that activates the forged request, such as through a social engineering tactic or by embedding the request in a way that the administrator unknowingly initiates it.

Remediation

Users are advised to update the User Registration & Membership plugin to version 4.4.9 or later.

Added: Jan 10, 2026, 9:18 AM
Updated: Jan 10, 2026, 9:18 AM

Vulnerability Rating

Custom Algorithm
spread
5.2
impact
0.6
exploitability
7.6
remediation
7.7
relevance
2.0
threat
4.8
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.