Extension WordPress
Vulnérabilités Simple User Registration
Cette page rassemble les failles publiées pour Simple User Registration, leurs plages de versions affectées et les correctifs signalés dans la base locale.
Historique de sécurité
CVE et vulnérabilités de Simple User Registration
6 fiches
Simple User Registration <= 6.7 – Authenticated (Subscriber+) Privilege Escalation via profile_save_field
The Simple User Registration plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 6.7 due to insufficient restriction on the 'profile_save_field' function. This makes it possible for authenticated attackers, with minimal permissions such…
*-6.7
6.8
27/01/2026
Simple User Registration <= 6.6 – Unauthenticated Stored Cross-Site Scripting
The Simple User Registration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'wpr_admin_msg' parameter in all versions up to, and including, 6.6 due to insufficient input sanitization and output escaping. This makes it possible for…
*-6.6
6.7
20/11/2025
Simple User Registration <= 6.4 – Authenticated (Contributor+) Privilege Escalation
The Simple User Registration plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.4. This makes it possible for authenticated attackers, with Contributor-level access and above, to gain access to administrative-level user…
*-6.4
Non indiqué
20/09/2025
Simple User Registration <= 6.3 – Unauthenticated Privilege Escalation
The Simple User Registration plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3. This is due to insufficient restrictions on user meta values that can be supplied during registration. This makes…
*-6.3
6.4
25/06/2025
Simple User Registration <= 5.5 – Missing Authorization to User Deletion
The Simple User Registration plugin for WordPress is vulnerable to unauthorized access to the user deletion feature due to a missing capability check in all versions up to, and including, 5.5. This makes it possible for unauthenticated attackers…
*-5.5
6.0
02/12/2024
Simple User Registration <= 6.7 – Missing Authorization to Account Takeover
The Simple User Registration plugin for WordPress is vulnerable to privilege escalation due to a missing capability check on a function in all versions up to, and including, 6.7. This makes it possible for unauthenticated attackers to takeover…
*-6.7
6.8
17/10/2024
Extensions également surveillés
WP Commander
Rechercher dans toute la base WordPress
Utilisez la recherche globale pour retrouver une extension, un thème, une CVE ou un identifiant de vulnérabilité.