Vulnerability record · CVE-2025-2563 · published 14 April 2025
CVE-2025-2563: User Registration & Membership WordPress plugin privilege escalation via role setting
Wpeverest · User Registration \& Membership
The User Registration & Membership WordPress plugin before 4.1.2 fails to prevent users from setting their own account role when the Membership Addon is enabled. This lets an unauthenticated attacker register an account with administrator privileges, effectively taking over the site.
Description
The User Registration & Membership WordPress plugin before 4.1.2 does not prevent users to set their account role when the Membership Addon is enabled, leading to a privilege escalation issue and allowing unauthenticated users to gain admin privileges
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Automated analysis
critical priorityUnauthenticated attackers can gain admin privileges, and a public exploit plus very high EPSS make active exploitation likely.
What it is
The User Registration & Membership WordPress plugin before 4.1.2 fails to prevent users from setting their own account role when the Membership Addon is enabled. This lets an unauthenticated attacker register an account with administrator privileges, effectively taking over the site.
Impact
An attacker gains full administrative control of the WordPress site, enabling complete compromise of content, users, and configuration.
Attack surface
Reachable over the network through the plugin's registration flow when the Membership Addon is active; no authentication or user interaction is required per the CVSS vector (PR:N/UI:N).
Exploitation
A public exploit reference exists (WPScan tagged Exploit), and EPSS is 0.485 (98.8th percentile), indicating high likelihood of exploitation; it is not listed in CISA KEV.
What to do
- Update the User Registration & Membership plugin to version 4.1.2 or later immediately.
- If patching is not possible, disable the Membership Addon or the plugin until it can be updated.
- Audit existing user accounts for unexpected administrator roles and remove any unauthorized admin users.
- Restrict or monitor new user registrations and role assignments on the site.
Detection
- Review WordPress user accounts for newly created administrators or role changes that do not match expected provisioning.
- Monitor web server and plugin logs for registration requests that include role or membership parameters.
- Alert on administrator account creation events, especially from unauthenticated or external sources.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://wpscan.com/vulnerability/2c0f62a1-9510-4f90-a297-17634e6c8b75/ | ExploitThird Party Advisory |
Track CVE-2025-2563 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2025-2563), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.