User Registration & Membership
cpe:2.3:a:wpeverest:user_registration_&_membership:*:*:*:*:wordpress:*:*
- < 5.2.2
An authentication bypass vulnerability has been identified in the User Registration & Membership WordPress plugin, affecting versions prior to 5.2.2. The vulnerability arises because the plugin does not verify the authenticity of webhook notifications from payment providers before processing them. This flaw allows unauthenticated attackers to fake a payment-approved event, thereby activating a paid membership subscription without actual payment. The issue is particularly relevant for subscriptions paid through PayPal, as the vulnerability exploits the plugin's webhook integration with this payment provider.
Exploiting this vulnerability allows attackers to activate paid membership subscriptions on behalf of users, granting access to premium content or features without any real payment being made.
To reproduce this vulnerability, first enable the Membership module in the User Registration & Membership WordPress plugin and publish at least one paid membership plan that can be purchased via PayPal. Once this is set up, an unauthenticated attacker can sign up for the paid plan through the public registration process, which will create a pending order and subscription. Afterward, the attacker can send a forged PayPal webhook event to the public webhook route, including a custom_id that references their own pending order. The request will be processed successfully, changing the order status to completed and activating the subscription, all without a genuine PayPal payment.
Users are advised to update the User Registration & Membership WordPress plugin to version 5.2.2 or later, where this vulnerability has been fixed.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.