VYPR

User Registration

by WordPress

Source repositories

CVEs (38)

  • CVE-2025-13367MedDec 15, 2025
    risk 0.35cvss 6.4epss 0.00

    The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple shortcode attributes in all versions up to, and including,…

  • CVE-2025-6831MedJul 22, 2025
    risk 0.35cvss 6.4epss 0.00

    The User Registration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's urcr_restrict shortcode in all versions up to, and including, 4.2.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it…

  • CVE-2024-3295MedMay 2, 2024
    risk 0.35cvss 6.5epss 0.01

    The User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the profile_pic_remove function in versions up to, and including, 3.1.5. This…

  • CVE-2021-24654MedOct 4, 2021
    risk 0.35cvss 5.4epss 0.01

    The User Registration WordPress plugin before 2.0.2 does not properly sanitise the user_registration_profile_pic_url value when submitted directly via the user_registration_update_profile_details AJAX action. This could allow any authenticated user, such as subscriber, to…

  • CVE-2026-74017MedSep 17, 2026
    risk 0.34cvss 5.3epss 0.00

    Unauthenticated Broken Access Control in User Registration <= 5.2.7 versions.

  • CVE-2026-73403MedAug 13, 2026
    risk 0.34cvss 5.3epss 0.00

    Unauthenticated Broken Access Control in User Registration <= 5.2.6 versions.

  • CVE-2026-2356MedFeb 26, 2026
    risk 0.34cvss 5.3epss 0.00

    The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.2 via the 'register_member' function, due to missing validation on the…

  • CVE-2023-29429MedDec 9, 2024
    risk 0.34cvss 5.3epss 0.00

    Missing Authorization vulnerability in WPEverest User Registration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects User Registration: from n/a through 2.3.2.1.

  • CVE-2023-5228MedNov 6, 2023
    risk 0.31cvss 4.8epss 0.01

    The User Registration WordPress plugin before 3.0.4.2 does not sanitize and escape some of its settings, which could allow high-privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in…

  • CVE-2026-24353MedJan 22, 2026
    risk 0.28cvss 4.3epss 0.00

    Missing Authorization vulnerability in wpeverest User Registration user-registration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects User Registration: from n/a through <= 4.4.9.

  • CVE-2025-14976MedJan 10, 2026
    risk 0.28cvss 5.4epss 0.00

    The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.4.8. This is due to missing…

  • CVE-2026-7651MedMay 28, 2026
    risk 0.27cvss 5.3epss 0.00

    The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.5. This is…

  • CVE-2026-6145MedMay 14, 2026
    risk 0.27cvss 5.3epss 0.00

    The User Registration & Membership plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 5.1.5. This is due to the is_admin_creation_process() method relying solely on the presence of action=createuser in the $_REQUEST superglobal…

  • CVE-2025-3281MedMay 6, 2025
    risk 0.27cvss 5.3epss 0.00

    The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.2.1 via the create_stripe_subscription() function, due to missing…

  • CVE-2025-9085MedSep 6, 2025
    risk 0.25cvss 4.9epss 0.00

    The User Registration & Membership plugin for WordPress is vulnerable to SQL Injection via the 's' parameter in version 4.3.0. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible…

  • CVE-2024-1720MedMar 7, 2024
    risk 0.24cvss 4.7epss 0.01

    The User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Display Name' parameter in all versions up to, and including, 3.1.4 due to insufficient input sanitization…

  • CVE-2026-3601MedMay 5, 2026
    risk 0.21cvss 4.3epss 0.00

    The User Registration & Membership plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `embed_form_action()` function in all versions up to, and including, 5.1.4. This makes it possible for authenticated attackers,…

  • CVE-2026-52701MedJun 26, 2026
    risk 0.00cvss 6.5epss 0.00

    Unauthenticated Broken Access Control in User Registration <= 5.2.2 versions.

Page 2 of 2