CVE-2025-2594
Last modified
CVE-2025-2594 is a high-severity vulnerability rated 8.1/10 on the CVSS scale. The User Registration & Membership WordPress plugin before 4.1.3 does not properly validate data in an AJAX action when the Membership Addon is enabled, allowing attackers to authenticate as any user, including administrators, by simply using the target account's user ID.. EPSS estimates a 7.25% chance of exploitation in the next 30 days.
Description
The User Registration & Membership WordPress plugin before 4.1.3 does not properly validate data in an AJAX action when the Membership Addon is enabled, allowing attackers to authenticate as any user, including administrators, by simply using the target account's user ID.
Metrics
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Wpeverest | User Registration \& Membership | < 4.1.3 |
| Wpeverest | User Registration \& Membership | < 5.1.3 |
References
- https://wpscan.com/vulnerability/1c1be47a-d5c0-4ac1-b9fd-475b382a7d8f/Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-2594?
How severe is CVE-2025-2594?
How do I fix CVE-2025-2594?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-25925A stored cross-scripting (XSS) vulnerability in Openmrs v2.4…4.8
- CVE-2025-25927A Cross-Site Request Forgery (CSRF) in Openmrs 2.4.3 Build 0…6.8
- CVE-2025-25928A Cross-Site Request Forgery (CSRF) in the component /admin/…8
- CVE-2025-25929A reflected cross-site scripting (XSS) vulnerability in the …5.4
- CVE-2025-2593A vulnerability has been found in FastCMS up to 0.1.5 and cl…6.3
- CVE-2025-25939Reprise License Manager 14.2 is vulnerable to reflected cros…6.1
- CVE-2025-25940VisiCut 2.1 allows code execution via Insecure XML Deseriali…9.8
- CVE-2025-25942An issue in Bento4 v1.6.0-641 allows an attacker to obtain s…6.5
- CVE-2025-25943Buffer Overflow vulnerability in Bento4 v.1.6.0-641 allows a…7.8
- CVE-2025-25944Buffer Overflow vulnerability in Bento4 v.1.6.0-641 allows a…7.3
- CVE-2025-25945An issue in Bento4 v1.6.0-641 allows an attacker to obtain s…6.5
- CVE-2025-25946An issue in Bento4 v1.6.0-641 allows an attacker to cause a …5.5
Are you affected by CVE-2025-2594?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
