Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 29 Apr 2025 21:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Wpeverest
Wpeverest user Registration \& Membership |
|
| Weaknesses | NVD-CWE-noinfo | |
| CPEs | cpe:2.3:a:wpeverest:user_registration_\&_membership:*:*:*:*:free:wordpress:*:* cpe:2.3:a:wpeverest:user_registration_\&_membership:*:*:*:*:pro:wordpress:*:* |
|
| Vendors & Products |
Wpeverest
Wpeverest user Registration \& Membership |
Mon, 14 Apr 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Mon, 14 Apr 2025 06:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | The User Registration & Membership WordPress plugin before 4.1.2 does not prevent users to set their account role when the Membership Addon is enabled, leading to a privilege escalation issue and allowing unauthenticated users to gain admin privileges | |
| Title | User Registration & Membership < 4.1.2- Unauthenticated Privilege Escalation | |
| References |
|
Status: PUBLISHED
Assigner: WPScan
Published:
Updated: 2025-08-27T12:00:20.215Z
Reserved: 2025-03-20T14:53:49.061Z
Link: CVE-2025-2563
Updated: 2025-04-14T14:20:19.939Z
Status : Analyzed
Published: 2025-04-14T06:15:16.333
Modified: 2025-04-29T20:32:12.237
Link: CVE-2025-2563
No data.
OpenCVE Enrichment
No data.