nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2025-3278 CVE-2025-3278
CRITICAL
UrbanGo Membership <= 1.0.4 - Unauthenticated Privilege Escalation
Record summary
CVE-2025-3278 has a selected CVSS score of 9.8 (critical).
Description
The UrbanGo Membership plugin for WordPress is vulnerable to privilege escalation in versions up to, and including, 1.0.4. This is due to the plugin allowing users who are registering new accounts to set their own role or by supplying 'user_register_role' field. This makes it possible for unauthenticated attackers to gain elevated privileges by creating an account with the administrator role.
Description source: CVE List
Exploitation context
Known exploitation
- VulnCheck KEV
- Listed · May 4, 2026 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
CISA SSVC decision
ExploitationNone
AutomatableYes
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Apr 21, 2025 · Source: CVE List
Affected products and versions
1| Product | Source | Version range | Status |
|---|---|---|---|
UrbanGo MembershipBrowse Edge-Themes / UrbanGo MembershipDefault status: unaffected | VulnCheck, CVE List | Through 1.0.4 | affected |
References
3themeforest.net
https://themeforest.net/item/urbango-directory-and-listing-wordpress-theme/22712624 wordfence.com
https://www.wordfence.com/threat-intel/vulnerabilities/id/913ffe0c-c8f8-4cda-be9a-96c056d4c4a8?source=cve