CVE-2025-3282 Details
Description
The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.1.3 via the user_registration_membership_register_member() due to missing validation on the 'membership_id' user controlled key. This makes it possible for unauthenticated attackers to update any user's membership to any other active or non-active membership type.
A vulnerability allowing Insecure Direct Object Reference has been identified in the User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress. This issue affects all versions through 4.1.3. The vulnerability arises in the user_registration_membership_register_member() function, where there is a lack of proper validation on the 'membership_id' key, which is controlled by users. As a result, unauthenticated attackers can manipulate membership types for any user, changing them to any active or inactive membership.
Users are advised to update the User Registration & Membership plugin to version 4.1.4 or a newer patched version.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Apr 14, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-639 | Authorization Bypass Through User-Controlled Key | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| wpeverest user registration & membership | < 4.1.4 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jul 8, 2025 | Initial Analysis | [email protected] |
| Apr 12, 2025 | New CVE Received | [email protected] |