Plugin Vulnerability Hub
Plugin 36 known issues Latest disclosed May 13, 2026

User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder Vulnerabilities

Review known vulnerability records for the WordPress plugin User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder (`user-registration`), including severity, CVE references, affected versions, and patch status.

Recent tracked CVEs on this page include CVE-2026-6145, CVE-2026-3601 and CVE-2026-6203, so operators can jump from disclosure to patch validation without scanning the full feed first.

Known Records
36
High or Critical
11
Patch Coverage
100%
Last Updated
May 13, 2026
Related Security Guides

Use these guides while reviewing User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder fixes

Pair this plugin vulnerability hub with practical WordPress hardening, scanner, and patch workflow guidance.

Patch Decision Workflow

How to prioritize User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder remediation

Use the hub as a decision layer before opening individual records: confirm whether the issue has a CVE, whether a fixed version exists, and whether the affected range overlaps production installs.

Search-Ready Records
35
1. Match the Package
Confirm the installed WordPress plugin slug is user-registration before acting on any CVE from this cluster.
2. Sort by Severity
Start with 11 high or critical records, then review medium and unrated findings with public references.
3. Check Patch Evidence
36 records include a patch path; verify compatibility before closing the finding.
4. Monitor Gaps
0 records still lack a listed fixed release, so keep this hub in the review queue.
Priority CVE Quick Links

Fast paths into User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder CVE reports

Start with the highest-signal CVE records for this WordPress plugin before scanning the full vulnerability feed.

Indexed CVEs
35
Tracked CVE Issue Type Affected Versions Fixed Version CVSS
CVE-2023-3342
User Registration <= 3.0.2 - Authenticated (Subscriber+) Arbitrary File Upload
Remote Code Execution Versions up to 3.0.2 3.0.2.1 CVSS 9.9
CVE-2026-32488
User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Res...
Remote Code Execution Versions up to 4.4.9 5.1.3 CVSS 9.8
CVE-2026-1492
User Registration & Membership <= 5.1.2 - Unauthenticated Privilege Escalation via M...
Privilege Escalation Versions up to 5.1.2 5.1.3 CVSS 9.8
CVE-2025-2563
User Registration & Membership <= 4.1.1 - Unauthenticated Privilege Escalation
Privilege Escalation Versions up to 4.1.1 4.1.2 CVSS 9.8
CVE-2024-2417
User Registration – Custom Registration Form, Login Form, and User Profile WordPress...
Privilege Escalation Versions up to 3.1.5 3.2.0 CVSS 8.8
CVE-2023-3343
User Registration <= 3.0.1 - Authenticated (Subscriber+) PHP Object Injection
Vulnerability Versions up to 3.0.1 3.0.2 CVSS 8.8
CVE-2022-3912
User Registration <= 2.2.4 - Authenticated (Subscriber+) Arbitrary File Upload
Remote Code Execution Versions up to 2.2.4 2.2.41 CVSS 8.8
CVE-2026-1779
User Registration & Membership <= 5.1.2 - Authentication Bypass
Vulnerability Versions up to 5.1.2 5.1.3 CVSS 8.1
CVE-2023-3342 Critical 3.0.2.1
CVE-2023-3342 User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder Remote Code Execution

User Registration <= 3.0.2 - Authenticated (Subscriber+) Arbitrary File Upload

CVE-2026-32488 Critical 5.1.3
CVE-2026-32488 User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder Remote Code Execution

User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder <= 4.4.9 - Unauthenticated Remote Code Execution

CVE-2026-1492 Critical 5.1.3
CVE-2026-1492 User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder Privilege Escalation

User Registration & Membership <= 5.1.2 - Unauthenticated Privilege Escalation via Membership Registration

CVE-2025-2563 Critical 4.1.2
CVE-2025-2563 User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder Privilege Escalation

User Registration & Membership <= 4.1.1 - Unauthenticated Privilege Escalation

CVE-2024-2417 High 3.2.0
CVE-2024-2417 User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder Privilege Escalation

User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin <= 3.1.5 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation

CVE-2023-3343 High 3.0.2
CVE-2023-3343 User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder Vulnerability

User Registration <= 3.0.1 - Authenticated (Subscriber+) PHP Object Injection

CVE-2022-3912 High 2.2.41
CVE-2022-3912 User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder Remote Code Execution

User Registration <= 2.2.4 - Authenticated (Subscriber+) Arbitrary File Upload

CVE-2026-1779 High 5.1.3
CVE-2026-1779 User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder Vulnerability

User Registration & Membership <= 5.1.2 - Authentication Bypass

Coverage Snapshot

What this page helps you verify fast

This hub clusters tracked records for User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder so operators can confirm whether a disclosed issue maps to the installed slug, version range, and patch path.

Patch Visibility
36 records include a published patch path, leaving 0 with no listed safe release yet.
Severity Mix
4 critical and 7 high severity findings.
Recent CVEs
CVE-2026-6145, CVE-2026-3601 and CVE-2026-6203
Reference Workflow
Jump from the hub into the full report when you need remediation notes, exploit context, CVSS vectors, or source references.
Triage First

Open the records most likely to drive action

These recent records surface the CVE strings, patch cues, and direct report links most operators need first.

Known Vulnerabilities

Reports for User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder

Sorted by latest disclosure date so newly published issues surface first.

Plugin Medium Patched: Yes CVE-2026-6145
CVE-2026-6145: User Registration & Membership <= 5.1.5 - Unauthenticated Missing Authorization to Admin Approval Bypass via 'action' Parameter

The User Registration & Membership plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 5.1.5. This is due to the is_admin_creation_process() method relying solely on the presence of action=createuser in the $_REQUEST superglobal witho...

Published
May 13, 2026
Patched Release
5.1.6
Affected Versions
Versions up to 5.1.5
Next Step
Update to 5.1.6 or newer if supported.
Plugin Medium Patched: Yes CVE-2026-3601
CVE-2026-3601: User Registration & Membership <= 5.1.4 - Missing Authorization to Authenticated (Contributor+) Limited Page Content Modification

The User Registration & Membership plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `embed_form_action()` function in all versions up to, and including, 5.1.4. This makes it possible for authenticated attackers, with...

Published
May 04, 2026
Patched Release
5.1.5
Affected Versions
Versions up to 5.1.4
Next Step
Update to 5.1.5 or newer if supported.
Plugin Medium Patched: Yes CVE-2026-6203
CVE-2026-6203: User Registration & Membership <= 5.1.4 - Unauthenticated Open Redirect via 'redirect_to_on_logout' Parameter

The User Registration & Membership plugin for WordPress is vulnerable to Open Redirect in versions up to and including 5.1.4. This is due to insufficient validation of user-supplied URLs passed via the 'redirect_to_on_logout' GET parameter before redirecting users. The `redirect_...

Published
Apr 13, 2026
Patched Release
5.1.5
Affected Versions
Versions up to 5.1.4
Next Step
Update to 5.1.5 or newer if supported.
Plugin Medium Patched: Yes CVE-2026-42652
CVE-2026-42652: User Registration <= 5.1.5 - Reflected Cross-Site Scripting

The User Registration plugin for WordPress is vulnerable to Reflected Cross-Site Scripting in versions up to, and including, 5.1.5 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in p...

Published
Apr 09, 2026
Patched Release
5.1.6
Affected Versions
Versions up to 5.1.5
Next Step
Update to 5.1.6 or newer if supported.
Plugin Medium Patched: Yes CVE-2026-1865
CVE-2026-1865: User Registration & Membership <= 5.1.2 - Authenticated (Subscriber+) SQL Injection via membership_ids[]

The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to SQL Injection via the ‘membership_ids[]’ parameter in all versions up to, and including,...

Published
Apr 07, 2026
Patched Release
5.1.3
Affected Versions
Versions up to 5.1.2
Next Step
Update to 5.1.3 or newer if supported.
Plugin Medium Patched: Yes CVE-2026-4056
CVE-2026-4056: User Registration & Membership <= 5.1.4 - Missing Authorization to Authenticated (Contributor+) Content Access Rule Manipulation

The User Registration & Membership plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Content Access Rules REST API endpoints in versions 5.0.1 through 5.1.4. This is due to the `check_permissions()` method only checki...

Published
Mar 23, 2026
Patched Release
5.1.5
Affected Versions
Versions up to 5.1.4
Next Step
Update to 5.1.5 or newer if supported.
Plugin Critical Patched: Yes CVE-2026-32488
CVE-2026-32488: User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder <= 4.4.9 - Unauthenticated Remote Code Execution

The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.4.9. This makes it possible...

Published
Mar 23, 2026
Patched Release
5.1.3
Affected Versions
Versions up to 4.4.9
Next Step
Update to 5.1.3 or newer if supported.
Plugin Critical Patched: Yes CVE-2026-1492
CVE-2026-1492: User Registration & Membership <= 5.1.2 - Unauthenticated Privilege Escalation via Membership Registration

The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to improper privilege management in all versions up to, and including, 5.1.2. This is due to the plug...

Published
Mar 02, 2026
Patched Release
5.1.3
Affected Versions
Versions up to 5.1.2
Next Step
Update to 5.1.3 or newer if supported.
Plugin Medium Patched: Yes CVE-2026-2356
CVE-2026-2356: User Registration & Membership <= 5.1.2 - Insecure Direct Object Reference to Unauthenticated Limited User Deletion

The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.2 via the 'register_member' function, due to missing validation on the 'mem...

Published
Feb 25, 2026
Patched Release
5.1.3
Affected Versions
Versions up to 5.1.2
Next Step
Update to 5.1.3 or newer if supported.
Plugin High Patched: Yes CVE-2026-1779
CVE-2026-1779: User Registration & Membership <= 5.1.2 - Authentication Bypass

The User Registration & Membership plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.1.2. This is due to incorrect authentication in the 'register_member' function. This makes it possible for unauthenticated attackers to log in a newl...

Published
Feb 25, 2026
Patched Release
5.1.3
Affected Versions
Versions up to 5.1.2
Next Step
Update to 5.1.3 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-67956
CVE-2025-67956: User Registration <= 4.4.6 - Missing Authorization

The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on a function in all versions up to, and inc...

Published
Jan 21, 2026
Patched Release
4.4.7
Affected Versions
Versions up to 4.4.6
Next Step
Update to 4.4.7 or newer if supported.
Plugin Medium Patched: Yes CVE-2025-14976
CVE-2025-14976: User Registration & Membership <= 4.4.8 - Cross-Site Request Forgery to Arbitrary Post Deletion

The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 4.4.8. This is due to missing or...

Published
Jan 09, 2026
Patched Release
4.4.9
Affected Versions
Versions up to 4.4.8
Next Step
Update to 4.4.9 or newer if supported.