WPEverest User Registration & Membership
cpe:2.3:a:wpeverest:user_registration_&_membership:*:*:*:*:wordpress:*:*
- <= 5.1.2
A vulnerability exists in the User Registration & Membership WordPress plugin, specifically in versions through 5.1.2. The issue arises from an Insecure Direct Object Reference (IDOR) in the 'register_member' function, where the 'member_id' key, controlled by the user, lacks proper validation. This flaw enables unauthenticated attackers to delete user accounts of individuals who have recently registered and possess the 'urm_user_just_created' user meta.
Exploitation of this vulnerability allows for the unauthorized deletion of user accounts, specifically those that have recently registered and have a certain user meta value set.
Users can update to version 5.1.3 or a newer patched version to address this vulnerability.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.