memberhero vulnerabilities
CVEs whose affected-version data names the memberhero package. Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2025-4334Critical· 9.8PoCThe Simple User Registration plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3
The Simple User Registration plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3. This is due to insufficient restrictions on user meta values that can be supplied during registration. Thi…
▾ Abyssalnajeebmedia · memberheroEPSS 2.3%via NVD
CVE-2024-49604Critical· 9.8Authentication Bypass Using an Alternate Path or Channel vulnerability in N-Media Simple User Registration wp-registration allows Authentication Bypass.This issue affects Simple User Registration: from n/a through <= 6.7.
Authentication Bypass Using an Alternate Path or Channel vulnerability in N-Media Simple User Registration wp-registration allows Authentication Bypass.This issue affects Simple User Registration: from n/a through <= 6.7.
▾ Midnightnajeebmedia · memberheroEPSS 0.53%via NVD