Impact
The WordPress plugin User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership contains stored XSS flaws in several shortcode attributes. An attacker who has contributor level access or higher can store malicious scripts that execute automatically in any browser that views a page containing the affected shortcode. This can allow session hijacking, credential theft, defacement, or the delivery of malware to site visitors.
Affected Systems
The vulnerability exists in all released versions of the plugin up to and including 4.4.6. It affects installations that have the plugin enabled within a WordPress site and rely on the shortcodes that expose unsecured attributes.
Risk and Exploitability
The CVSS score of 6.4 indicates a moderate impact, but the EPSS score of < 1% suggests that actual exploitation is unlikely at the moment. The flaw is not listed in CISA’s KEV catalog, so there is no evidence of active widespread exploitation. However, because the exploit requires contributor‑level rights, the risk escalates if an organization has many users with such privileges or if role permissions are not tightly controlled.
OpenCVE Enrichment