---
id: CVE-2025-4334
title: >-
  The Simple User Registration plugin for WordPress is vulnerable to Privilege
  Escalation in all versions up to, and including, 6.3
summary: >-
  The Simple User Registration plugin for WordPress is vulnerable to Privilege
  Escalation in all versions up to, and including, 6.3. This is due to
  insufficient restrictions on user meta values that can be supplied during
  registration. Thi…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-269
vendor: najeebmedia
product: memberhero
affected:
  - memberhero <= 6.3
published: '2025-06-26'
updated: '2026-08-11'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-4334'
references:
  - url: >-
      https://plugins.trac.wordpress.org/browser/wp-registration/trunk/inc/classes/class.register.php#L135
    label: security@wordfence.com
  - url: 'https://plugins.trac.wordpress.org/changeset/3327946/'
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/c211e0c0-3086-43d2-853c-489f9c42b0ab?source=cve
    label: security@wordfence.com
tags:
  - nvd
  - exploit-available
epss: 0.02268
epssPercentile: 0.82282
ingestedAt: '2026-08-11T16:47:03.617Z'
exploits:
  github: 3
  githubRepos:
    - 'https://github.com/Nxploited/CVE-2025-4334'
    - 'https://github.com/0xgh057r3c0n/CVE-2025-4334'
    - 'https://github.com/vinodwick/CVE-2025-4334'
  nuclei:
    - CVE-2025-4334
  checkedAt: '2026-09-23T07:13:36.073Z'
exploitAvailable: true
---

## Overview

The Simple User Registration plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3. This is due to insufficient restrictions on user meta values that can be supplied during registration. This makes it possible for unauthenticated attackers to register as an administrator.

## Affected

- `memberhero <= 6.3`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
