The User Registration & Membership WordPress plugin before 4.1.2 does not prevent users to set their account role when the Membership Addon is enabled, leading to a privilege escalation issue and allowing unauthenticated users to gain admin privileges
CVE ID: CVE-2025-2563
Vendor: Unknown
Product: User Registration & Membership
http/cves/2025/CVE-2025-2563.yaml
EPSS Score: 11.25% (probability of being exploited)
EPSS Percentile: 93.09% (scored less or equal to compared to others)
EPSS Date: 2025-04-16 (when was this score calculated)