Extension WordPress
Vulnérabilités User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder, page 2
Cette page rassemble les failles publiées pour User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder
50 fiches
User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder <= 4.4.9 – Unauthenticated Remote Code Execution
The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.4.9.…
*-4.4.9
5.1.3
23/03/2026
User Registration & Membership <= 5.1.2 – Unauthenticated Privilege Escalation via Membership Registration
The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to improper privilege management in all versions up to, and including, 5.1.2. This…
*-5.1.2
5.1.3
02/03/2026
User Registration & Membership <= 5.1.2 – Insecure Direct Object Reference to Unauthenticated Limited User Deletion
The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.2 via the 'register_member' function, due to…
*-5.1.2
5.1.3
25/02/2026
User Registration & Membership <= 5.1.2 – Authentication Bypass
The User Registration & Membership plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.1.2. This is due to incorrect authentication in the 'register_member' function. This makes it possible for unauthenticated attackers to…
*-5.1.2
5.1.3
25/02/2026
User Registration <= 4.4.6 – Missing Authorization
The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in…
*-4.4.6
4.4.7
21/01/2026
User Registration & Membership <= 4.4.8 – Cross-Site Request Forgery to Arbitrary Post Deletion
The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.4.8. This…
*-4.4.8
4.4.9
09/01/2026
User Registration <= 4.4.9 – Authenticated (Subscriber+) Arbitrary Shortcode Execution
The The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including,…
*-4.4.9
5.0
08/01/2026
User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin <= 4.4.6 – Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes
The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple shortcode attributes in all versions up to, and…
*-4.4.6
4.4.7
15/12/2025
User Registration & Membership <= 4.3.0 – Authenticated (Admin+) SQL Injection
The User Registration & Membership plugin for WordPress is vulnerable to SQL Injection via the 's' parameter in version 4.3.0. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the…
*-4.3.0
4.4.0
05/09/2025
User Registration <= 4.2.4 – Authenticated (Contributor+) Stored Cross-Site Scripting via urcr_restrict Shortcode
The User Registration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's urcr_restrict shortcode in all versions up to, and including, 4.2.4 due to insufficient input sanitization and output escaping on user supplied attributes. This…
*-4.2.4
4.3.0
21/07/2025
User Registration & Membership – Custom Registration Form, Login Form, and User Profile <= 4.2.1 – Insecure Direct Object Reference to Unauthenticated Limited User Deletion
The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.2.1 via the create_stripe_subscription() function, due to…
*-4.2.1
4.2.2
05/05/2025
User Registration <= 4.1.5 – Reflected Cross-Site Scripting
The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 4.1.5 due to insufficient input sanitization and output…
*-4.1.5
4.2.0
22/04/2025
User Registration & Membership – Custom Registration Form, Login Form, and User Profile <= 4.1.3 – Insecure Direct Object Reference to Authenticated (Subscriber+) User Password Update
The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.1.3 via the user_registration_update_profile_details() due to missing…
*-4.1.3
4.1.4
11/04/2025
User Registration & Membership – Custom Registration Form, Login Form, and User Profile <= 4.1.3 – Insecure Direct Object Reference to Unauthenticated Membership Modification
The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.1.3 via the user_registration_membership_register_member() due to missing…
*-4.1.3
4.1.4
11/04/2025
User Registration & Membership <= 4.1.2 – Authentication Bypass
The User Registration & Membership plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 4.1.2. This is due to incorrect authentication in the 'confirm_payment()' function. This makes it possible for unauthenticated attackers to…
*-4.1.2
4.1.3
01/04/2025
User Registration <= 4.0.3 – Authenticated (Administrator+) Stored Cross-Site Scripting
The User Registration plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to, and including, 4.0.3 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access and…
*-4.0.3
4.0.4
27/03/2025
User Registration & Membership <= 4.1.1 – Unauthenticated Privilege Escalation
The User Registration & Membership plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 4.1.1. This is due to insufficient restrictions on role type in the 'prepare_members_data()' function. This makes it possible for…
*-4.1.1
4.1.2
24/03/2025
User Registration & Membership – Custom Registration Form, Login Form, and User Profile <= 4.0.4 – Reflected Cross-Site Scripting
The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 's' parameter in all versions up to, and including, 4.0.4 due to insufficient…
*-4.0.4
4.1.0
27/02/2025
User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin <= 3.2.0.1 – Missing Authorization to Privilege Escalation
The User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'import_form_action' function in versions up to,…
*-3.2.0.1
3.2.1
31/05/2024
User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin <= 3.1.5 – Missing Authorization to Authenticated (Subscriber+) Privilege Escalation
The User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on the form_save_action() function in all versions up to, and…
*-3.1.5
3.2.0
19/04/2024
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.