User Registration & Membership
cpe:2.3:a:wpeverest:user_registration_&_membership:*:*:*:*:wordpress:*:*
- < 4.1.2
A privilege escalation vulnerability has been identified in the User Registration & Membership WordPress plugin, affecting versions prior to 4.1.2. When the Membership Addon is enabled, the plugin allows users to arbitrarily set their account roles. This flaw enables unauthenticated users to gain administrative privileges on the site.
Exploitation of this vulnerability allows unauthenticated users to gain admin privileges on the WordPress site.
Users can update to User Registration & Membership version 4.1.2 or later to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.