Логотип exploitDog
bind:CVE-2025-2594
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2025-2594

Количество 2

Количество 2

nvd логотип

CVE-2025-2594

10 месяцев назад

The User Registration & Membership WordPress plugin before 4.1.3 does not properly validate data in an AJAX action when the Membership Addon is enabled, allowing attackers to authenticate as any user, including administrators, by simply using the target account's user ID.

CVSS3: 8.1
EPSS: Низкий
github логотип

GHSA-hmpr-r93w-5j44

10 месяцев назад

The User Registration & Membership WordPress plugin before 4.1.3 does not properly validate data in an AJAX action when the Membership Addon is enabled, allowing attackers to authenticate as any user, including administrators, by simply using the target account's user ID.

CVSS3: 8.1
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2025-2594

The User Registration & Membership WordPress plugin before 4.1.3 does not properly validate data in an AJAX action when the Membership Addon is enabled, allowing attackers to authenticate as any user, including administrators, by simply using the target account's user ID.

CVSS3: 8.1
5%
Низкий
10 месяцев назад
github логотип
GHSA-hmpr-r93w-5j44

The User Registration & Membership WordPress plugin before 4.1.3 does not properly validate data in an AJAX action when the Membership Addon is enabled, allowing attackers to authenticate as any user, including administrators, by simply using the target account's user ID.

CVSS3: 8.1
5%
Низкий
10 месяцев назад

Уязвимостей на страницу