The Simple User Registration plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3. This is due to insufficient restrictions on user meta values that can be supplied during registration. This makes it possible for unauthenticated attackers to register as an administrator.
History

Fri, 27 Jun 2025 15:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 26 Jun 2025 02:15:00 +0000

Type Values Removed Values Added
Description The Simple User Registration plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3. This is due to insufficient restrictions on user meta values that can be supplied during registration. This makes it possible for unauthenticated attackers to register as an administrator.
Title Simple User Registration <= 6.3 - Unauthenticated Privilege Escalation
Weaknesses CWE-269
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published: 2025-06-26T02:06:34.765Z

Updated: 2025-06-27T14:51:55.539Z

Reserved: 2025-05-05T15:26:58.510Z

Link: CVE-2025-4334

cve-icon Vulnrichment

Updated: 2025-06-27T14:41:12.078Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-06-26T02:15:21.173

Modified: 2025-06-26T18:57:43.670

Link: CVE-2025-4334

cve-icon Redhat

No data.