Missing Authorization
17 records38.6%First: 2023. Latest: 2026.
Plugin security history
The Wordfence Intelligence dataset currently contains 44 vulnerability records associated with User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder, published between 2019 and 2026.
Dataset last synchronized: 2026-08-02 09:41:47 UTC
At a glance
| Year | Records | Relative volume |
|---|---|---|
| 2019 | 1 | |
| 2022 | 1 | |
| 2023 | 6 | |
| 2024 | 4 | |
| 2025 | 11 | |
| 2026 | 21 |
| Severity | Records | Share |
|---|---|---|
| Critical | 4 | 9.1% |
| High | 8 | 18.2% |
| Medium | 32 | 72.7% |
First: 2023. Latest: 2026.
First: 2019. Latest: 2026.
First: 2025. Latest: 2026.
First: 2023. Latest: 2026.
First: 2025. Latest: 2026.
First: 2022. Latest: 2023.
First: 2025. Latest: 2026.
First: 2026. Latest: 2026.
Patch status reflects the latest successfully synchronized source dataset and must be checked against the installed version.
5.2.15.2.25.2.35.1.65.1.55.1.34.4.95.04.4.74.4.04.3.04.2.24.2.04.1.44.1.34.0.44.1.24.1.03.2.13.2.03.1.53.0.4.23.0.2.13.0.22.3.32.3.12.2.411.5.6Ranges are deduplicated by source range record and shown with the associated disclosure and known patched versions.
| Affected range | Vulnerability | Published | Patched version | Severity |
|---|---|---|---|---|
*-4.1.5 | User Registration <= 4.1.5 - Reflected Cross-Site Scripting | April 22, 2025 | 4.2.0 | Medium |
*-4.1.3 | User Registration & Membership – Custom Registration Form, Login Form, and User Profile <= 4.1.3 - Insecure Direct Object Reference to Authenticated (Subscriber+) User Password Update | April 11, 2025 | 4.1.4 | Medium |
*-4.1.3 | User Registration & Membership – Custom Registration Form, Login Form, and User Profile <= 4.1.3 - Insecure Direct Object Reference to Unauthenticated Membership Modification | April 11, 2025 | 4.1.4 | Medium |
*-4.1.2 | User Registration & Membership <= 4.1.2 - Authentication Bypass | April 1, 2025 | 4.1.3 | High |
*-4.0.3 | User Registration <= 4.0.3 - Authenticated (Administrator+) Stored Cross-Site Scripting | March 27, 2025 | 4.0.4 | Medium |
*-4.1.1 | User Registration & Membership <= 4.1.1 - Unauthenticated Privilege Escalation | March 24, 2025 | 4.1.2 | Critical |
*-4.0.4 | User Registration & Membership – Custom Registration Form, Login Form, and User Profile <= 4.0.4 - Reflected Cross-Site Scripting | February 27, 2025 | 4.1.0 | Medium |
*-3.2.0.1 | User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin <= 3.2.0.1 - Missing Authorization to Privilege Escalation | May 31, 2024 | 3.2.1 | High |
*-3.1.5 | User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin <= 3.1.5 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation | April 19, 2024 | 3.2.0 | High |
*-3.1.5 | User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin <= 3.1.5 - Missing Authorization to Unauthenticated Media Deletion | April 15, 2024 | 3.2.0 | Medium |
*-3.1.4 | User Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin <= 3.1.4 - Unauthenticated Stored Self-Based Cross-Site Scripting | March 6, 2024 | 3.1.5 | Medium |
*-3.0.4.1 | User Registration – Custom Registration Form, Login Form And User Profile For WordPress <= 3.0.4.1 - Authenticated (Admin+) Stored Cross-Site Scripting | October 16, 2023 | 3.0.4.2 | Medium |
*-3.0.2 | User Registration <= 3.0.2 - Authenticated (Subscriber+) Arbitrary File Upload | July 4, 2023 | 3.0.2.1 | Critical |
*-3.0.1 | User Registration <= 3.0.1 - Authenticated (Subscriber+) PHP Object Injection | June 29, 2023 | 3.0.2 | High |
*-2.3.2.1 | User Registration <= 2.3.2.1 - Missing Authorization via send_test_email | April 6, 2023 | 2.3.3 | Medium |
*-2.3.2.1 | User Registration <= 2.3.2.1 - PHP Object Injection | March 21, 2023 | 2.3.3 | High |
*-2.3.0 | User Registration <= 2.3.0 - Authenticated (Administrator+) Stored Cross Site Scripting | January 20, 2023 | 2.3.1 | Medium |
*-2.2.4 | User Registration <= 2.2.4 - Authenticated (Subscriber+) Arbitrary File Upload | November 21, 2022 | 2.2.41 | High |
*-1.5.5 | User Registration <= 1.5.5 - Cross-Site Scripting | January 9, 2019 | 1.5.6 | Medium |
Selected source records
Published: June 26, 2026
Published: June 26, 2026
Published: June 25, 2026
Published: June 22, 2026
Published: June 22, 2026
Published: June 22, 2026
Published: May 28, 2026
Published: May 27, 2026
Published: July 4, 2023
Published: March 23, 2026
Published: March 2, 2026
Published: March 24, 2025
Published: June 29, 2023
Published: November 21, 2022
Published: April 19, 2024
Published: April 1, 2025
Running an affected version does not prove that a website was compromised. Suspicious redirects, unknown administrators, injected content, unexpected files or recurring malware may require a manual investigation.
Vulnerability data: Wordfence Intelligence. Analysis and practical guidance: 3Zero Digital.
This page aggregates active Production Feed records. Counts are not software-quality rankings, and an affected version does not prove exploitation or infection. Read the full methodology.