CVE-2025-4334

CRITICAL NUCLEI

Najeebmedia Simple User Registration - Improper Privilege Management

Title source: rule

Description

The Simple User Registration plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3. This is due to insufficient restrictions on user meta values that can be supplied during registration. This makes it possible for unauthenticated attackers to register as an administrator.

Exploits (5)

nomisec WORKING POC 7 stars
by Nxploited · poc
https://github.com/Nxploited/CVE-2025-4334
github WORKING POC 4 stars
by ctkqiang · gopoc
https://github.com/ctkqiang/CVE-Exploits/tree/main/CVE-2025-4334
nomisec WORKING POC 3 stars
by 0xgh057r3c0n · poc
https://github.com/0xgh057r3c0n/CVE-2025-4334
github WORKING POC 1 stars
by vinodwick · pythonpoc
https://github.com/vinodwick/CVE-2025-4334
github WORKING POC
by Boshe99 · pythonpoc
https://github.com/Boshe99/CVE-Exploits/tree/main/CVE-2025-4334

Nuclei Templates (1)

Simple User Registration <= 6.3 - Unauthenticated Privilege Escalation
CRITICALVERIFIEDby pussycat0x
Shodan: http.component:"wordpress" && http.html:"/wp-content/plugins/simple-user-registration/"

Scores

CVSS v3 9.8
EPSS 0.2808
EPSS Percentile 96.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Classification

CWE
CWE-269
Status published

Affected Products (1)

najeebmedia/simple_user_registration < 6.3

Timeline

Published Jun 26, 2025
Tracked Since Feb 18, 2026