Plugin Vulnerability Hub
Plugin 30 known issues Latest disclosed Mar 23, 2026

User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder Vulnerabilities

Review known vulnerability records for the WordPress plugin User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder (`user-registration`), including severity, CVE references, affected versions, and patch status.

Known Records
30
High or Critical
10
Linked CVEs
29
Last Updated
Mar 23, 2026
Coverage Snapshot

What this page helps you verify fast

This hub clusters every indexed record for User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder so operators can quickly confirm whether a disclosed issue maps to the installed slug and version range.

Patch Visibility
30 records include a published patch path.
Severity Mix
3 critical and 7 high severity findings.
Reference Workflow
Jump from the hub into the full report when you need remediation notes, CVSS vector details, or source references.
Known Vulnerabilities

Reports for User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder

Sorted by latest disclosure date so newly published issues surface first.

Plugin Medium Patched: Yes CVE-2026-4056
User Registration & Membership <= 5.1.4 - Missing Authorization to Authenticated (Contributor+) Content Access Rule Manipulation

The User Registration & Membership plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Content Access Rules REST API endpoints in versions 5.0.1 through 5.1.4. This is due to the `check_permissions()` method only checki...

Published
Mar 23, 2026
Patched Release
5.1.5
Affected Versions
Versions up to 5.1.4
Next Step
Update to 5.1.5 or newer if supported.
Plugin Critical Patched: Yes CVE-2026-1492
User Registration & Membership <= 5.1.2 - Unauthenticated Privilege Escalation via Membership Registration

The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to improper privilege management in all versions up to, and including, 5.1.2. This is due to the plug...

Published
Mar 02, 2026
Patched Release
5.1.3
Affected Versions
Versions up to 5.1.2
Next Step
Update to 5.1.3 or newer if supported.
Plugin Medium Patched: Yes CVE-2026-2356
User Registration & Membership <= 5.1.2 - Insecure Direct Object Reference to Unauthenticated Limited User Deletion

The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.2 via the 'register_member' function, due to missing validation on the 'mem...

Published
Feb 25, 2026
Patched Release
5.1.3
Affected Versions
Versions up to 5.1.2
Next Step
Update to 5.1.3 or newer if supported.
Plugin High Patched: Yes CVE-2026-1779
User Registration & Membership <= 5.1.2 - Authentication Bypass

The User Registration & Membership plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.1.2. This is due to incorrect authentication in the 'register_member' function. This makes it possible for unauthenticated attackers to log in a newl...

Published
Feb 25, 2026
Patched Release
5.1.3
Affected Versions
Versions up to 5.1.2
Next Step
Update to 5.1.3 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-67956
User Registration <= 4.4.6 - Missing Authorization

The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and inc...

Published
Jan 21, 2026
Patched Release
4.4.7
Affected Versions
Versions up to 4.4.6
Next Step
Update to 4.4.7 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-14976
User Registration & Membership <= 4.4.8 - Cross-Site Request Forgery to Arbitrary Post Deletion

The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.4.8. This is due to missing or...

Published
Jan 09, 2026
Patched Release
4.4.9
Affected Versions
Versions up to 4.4.8
Next Step
Update to 4.4.9 or newer if supported.
Plugin Medium Patched: Yes CVE-2026-24353
User Registration <= 4.4.9 - Authenticated (Subscriber+) Arbitrary Shortcode Execution

The The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 4.4.9. This is du...

Published
Jan 08, 2026
Patched Release
5.0
Affected Versions
Versions up to 4.4.9
Next Step
Update to 5.0 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-13367
User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin <= 4.4.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode Attributes

The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin for WordPress is vulnerable to Stored Cross-Site Scripting via multiple shortcode attributes in all versions up to, and including, 4.4.6...

Published
Dec 15, 2025
Patched Release
4.4.7
Affected Versions
Versions up to 4.4.6
Next Step
Update to 4.4.7 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-9085
User Registration & Membership <= 4.3.0 - Authenticated (Admin+) SQL Injection

The User Registration & Membership plugin for WordPress is vulnerable to SQL Injection via the 's' parameter in version 4.3.0. This is due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible...

Published
Sep 05, 2025
Patched Release
4.4.0
Affected Versions
Versions up to 4.3.0
Next Step
Update to 4.4.0 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-6831
User Registration <= 4.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via urcr_restrict Shortcode

The User Registration plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's urcr_restrict shortcode in all versions up to, and including, 4.2.4 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possi...

Published
Jul 21, 2025
Patched Release
4.3.0
Affected Versions
Versions up to 4.2.4
Next Step
Update to 4.3.0 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-3281
User Registration & Membership – Custom Registration Form, Login Form, and User Profile <= 4.2.1 - Insecure Direct Object Reference to Unauthenticated Limited User Deletion

The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 4.2.1 via the create_stripe_subscription() function, due to missing validation...

Published
May 05, 2025
Patched Release
4.2.2
Affected Versions
Versions up to 4.2.1
Next Step
Update to 4.2.2 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-39400
User Registration <= 4.1.5 - Reflected Cross-Site Scripting

The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in all versions up to, and including, 4.1.5 due to insufficient input sanitization and output escaping. This makes it p...

Published
Apr 22, 2025
Patched Release
4.2.0
Affected Versions
Versions up to 4.1.5
Next Step
Update to 4.2.0 or newer if supported.