CVE-2026-3601
User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder
Minimum safe version
5.1.6
Update to 5.1.6 or later to address 38 fixable vulnerabilities
CVE-2026-42652
User Registration & Membership <= 4.3.0 - Authenticated (Admin+) SQL Injection
User Registration & Membership <= 5.1.2 - Insecure Direct Object Reference to Unauthenticated Limited User Deletion
User Registration & Membership <= 5.1.2 - Authentication Bypass
User Registration & Membership <= 5.1.2 - Unauthenticated Privilege Escalation via Membership Registration
CVE-2026-6203
User Registration & Membership <= 5.1.4 - Missing Authorization to Authenticated (Contributor+) Content Access Rule Manipulation
User Registration & Membership <= 5.1.2 - Authenticated (Subscriber+) SQL Injection via membership_ids[]
CVE-2026-32488
CVE-2026-24353
CVE-2025-67956
CVE-2025-14976
CVE-2025-13367
User Registration <= 4.2.4 - Authenticated (Contributor+) Stored Cross-Site Scripting via urcr_restrict Shortcode
User Registration & Membership – Custom Registration Form, Login Form, and User Profile <= 4.2.1 - Insecure Direct Object Reference to Unauthenticated Limited User Deletion
CVE-2025-39400
User Registration & Membership – Custom Registration Form, Login Form, and User Profile <= 4.1.3 - Insecure Direct Object Reference to Unauthenticated Membership Modification
User Registration & Membership – Custom Registration Form, Login Form, and User Profile <= 4.1.3 - Insecure Direct Object Reference to Authenticated (Subscriber+) User Password Update
User Registration & Membership <= 4.1.2 - Authentication Bypass
CVE-2025-30899
User Registration & Membership <= 4.1.1 - Unauthenticated Privilege Escalation
WordPress User Registration Plugin <= 4.0.4 is vulnerable to Cross Site Scripting (XSS)
WordPress User Registration Plugin <= 3.2.0.1 is vulnerable to Broken Access Control
CVE-2024-2417
CVE-2024-3295
CVE-2024-1720
WordPress User Registration Plugin < 3.0.4.2 is vulnerable to Cross Site Scripting (XSS)
CVE-2023-3342
CVE-2023-3343
CVE-2023-29429
CVE-2023-27459
CVE-2023-23987
User Registration <= 1.5.5 - Cross-Site Scripting
CVE-2022-3912
User Registration <= 1.5.5 - Authenticated Cross-Site Scripting (XSS)
WordPress User Registration plugin <= 1.5.5 - Authenticated Cross-Site Scripting (XSS) vulnerability
CVE-2021-24654