Home
Home
Trends
Trends
Vulnerabilities
Vulnerabilities
News
News
Researchers
Researchers
Why dbugs?
Why dbugs?
Settings

Wpeverest

#50063of 56,330
5.3Total CVSS
Vulnerabilities · 1
PT-2025-19903
5.3
2025-05-06
WordPress · User Registration & Membership · CVE-2025-3281
**Name of the Vulnerable Software and Affected Versions** User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress versions prior to 4.2.2 **Description** The issue is related to an Insecure Direct Object Reference in the create stripe subscription() function, due to missing validation on the `member id` user-controlled key. This allows unauthenticated attackers to delete arbitrary user accounts registered through the plugin. **Recommendations** For versions prior to 4.2.2, update to version 4.2.2 or later to resolve the issue. As a temporary workaround, consider disabling the `create stripe subscription()` function until a patch is available.