Impact
The WordPress plugin User Registration & Membership up to version 5.1.2 fails to enforce a server‑side allowlist for the user‑supplied role during membership registration. An unauthenticated attacker can deliver a role value that grants administrator privileges, creating a fully privileged account without authenticating with the site. This allows the attacker to perform actions that are available to administrators in WordPress.
Affected Systems
The vulnerability affects the wpeverest User Registration & Membership plugin for WordPress, across all releases up to and including 5.1.2. Any WordPress site running a vulnerable version and permitting open membership registration is susceptible. The product is listed under the wpeverest vendor umbrella.
Risk and Exploitability
The flaw is rated CVSS 9.8, indicating critical severity. An EPSS score of 24% indicates that the exploit is likely to be used in the wild. The vulnerability is not currently listed in the CISA KEV catalog. Attackers can exploit the flaw simply by visiting the site’s registration page and submitting a form containing a role assignment of "administrator". No authentication or privileged access is required to initiate the attack, making it highly exploitable under typical conditions.
OpenCVE Enrichment