Extension WordPress
Vulnérabilités User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder
Cette page rassemble les failles publiées pour User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder
48 fiches
User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder <= 5.2.6 – Missing Authorization
The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function…
*-5.2.6
5.2.7
14/08/2026
User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder <= 5.2.6 – Missing Authorization
The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function…
*-5.2.6
5.2.7
13/08/2026
User Registration & Membership <= 5.2.5 – Missing Authorization to Unauthenticated Account Creation While Registration Disabled
The User Registration & Membership plugin for WordPress is vulnerable to unauthorized access in versions up to, and including, 5.2.5. This is due to a missing capability check on a function. This makes it possible for unauthenticated attackers…
*-5.2.5
5.2.6
27/07/2026
User Registration & Membership <= 5.2.2 – Missing Authorization to Unauthenticated User Deletion via Stripe Handler
The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.2.2. This…
*-5.2.2
5.2.3
26/06/2026
User Registration & Membership <= 5.2.2 – Unauthenticated Privilege Escalation
The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 5.2.2. This…
*-5.2.2
5.2.3
26/06/2026
User Registration & Membership <= 5.2.0 – Missing Authorization to Unauthenticated Payment Bypass
The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to unauthorized modification of data due to missing validation checks in the…
*-5.2.0
5.2.1
25/06/2026
User Registration & Membership <= 5.2.1 – Unauthenticated PayPal Bypass to Membership Activation
The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to payment bypass in all versions up to, and including, 5.2.1. This…
*-5.2.1
5.2.2
22/06/2026
User Registration & Membership <= 5.2.1 – Authenticated (Subscriber+) Insecure Direct Object Reference to Membership Tier Modification
The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including,…
*-5.2.1
5.2.2
22/06/2026
User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder <= 5.2.2 – Missing Authorization
The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function…
*-5.2.2
5.2.3
22/06/2026
User Registration & Membership <= 5.1.0 – Unauthenticated Payment Bypass
The User Registration & Membership plugin for WordPress is vulnerable to Payment Bypass in versions up to, and including, 5.1.0. This is due to a lack of server-side payment verification. This makes it possible for unauthenticated attackers to…
*-5.1.0
5.2.0
11/06/2026
User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder <= 5.1.2 – Missing Authorization
The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function…
*-5.1.2
5.1.3
28/05/2026
User Registration & Membership <= 5.1.5 – Authenticated (Subscriber+) Insecure Direct Object Reference to Arbitrary Media Deletion via 'profile-pic-url' Parameter
The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including,…
*-5.1.5
5.1.6
27/05/2026
User Registration & Membership <= 5.1.5 – Unauthenticated Missing Authorization to Admin Approval Bypass via 'action' Parameter
The User Registration & Membership plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 5.1.5. This is due to the is_admin_creation_process() method relying solely on the presence of action=createuser in the $_REQUEST…
*-5.1.5
5.1.6
13/05/2026
User Registration & Membership <= 5.1.4 – Missing Authorization to Authenticated (Contributor+) Limited Page Content Modification
The User Registration & Membership plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `embed_form_action()` function in all versions up to, and including, 5.1.4. This makes it possible for…
*-5.1.4
5.1.5
04/05/2026
User Registration & Membership <= 5.1.4 – Unauthenticated Open Redirect via 'redirect_to_on_logout' Parameter
The User Registration & Membership plugin for WordPress is vulnerable to Open Redirect in versions up to and including 5.1.4. This is due to insufficient validation of user-supplied URLs passed via the 'redirect_to_on_logout' GET parameter before redirecting users.…
*-5.1.4
5.1.5
13/04/2026
User Registration <= 5.1.5 – Reflected Cross-Site Scripting
The User Registration plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 5.1.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web…
*-5.1.5
5.1.6
09/04/2026
User Registration & Membership <= 5.1.2 – Authenticated (Subscriber+) SQL Injection via membership_ids[]
The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to SQL Injection via the ‘membership_ids[]’ parameter in all versions up to,…
*-5.1.2
5.1.3
08/04/2026
User Registration & Membership <= 5.1.4 – Missing Authorization to Authenticated (Contributor+) Content Access Rule Manipulation
The User Registration & Membership plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Content Access Rules REST API endpoints in versions 5.0.1 through 5.1.4. This is due to…
*-5.1.4
5.1.5
23/03/2026
User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder <= 4.4.9 – Unauthenticated Remote Code Execution
The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.4.9.…
*-4.4.9
5.1.3
23/03/2026
User Registration & Membership <= 5.1.2 – Unauthenticated Privilege Escalation via Membership Registration
The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to improper privilege management in all versions up to, and including, 5.1.2. This…
*-5.1.2
5.1.3
02/03/2026
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.