CVE-2024-4958 HIGH

CVE-2024-4958: User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin <= 3.2.0.1 - Missing Authorization to Privilege Escalation

Vendor Wpeverest
Product User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder
Weakness CWE-862 · Missing authorization
Published June 1, 2024
Last update April 8, 2026

CVSS base score

7.1/10
Attack vector Network
Attack complexity High
Privileges required Low
User interaction Required
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

The User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'import_form_action' function in versions up to, and including, 3.2.0.1. This makes it possible for authenticated attackers, with contributor-level permissions and above, to import a registration form with a default user role of administrator. If an administrator approves or publishes a post or page with the shortcode to the imported form, any user can register as an administrator.

Explanation of Vulnerability in Simple Terms

02Summary

A missing authorization check in the User Registration & Membership plugin allows authenticated users with low privileges to perform actions they should not be able to access. An attacker must be logged in and trick a victim into clicking a malicious link. The vulnerability can lead to unauthorized data modification, information disclosure, or service disruption on affected sites.

What an attacker can do

03Attacker Capabilities

Modify data, read sensitive information, or disrupt the site if logged in and victim clicks a link.

Potential impact on your site

04Site Impact

Unauthorized users may modify site content, access private data, or cause downtime without proper permission checks.

Conditions required to exploit

05Prerequisites

Attacker must have a low-privilege account and the victim must click a malicious link.

Key dates

06Disclosure timeline

June 1, 2024 CVE published
April 8, 2026 Record updated

Related vulnerabilities

08Related CVE