CVE-2025-4334
CRITICAL NUCLEINajeebmedia Simple User Registration - Improper Privilege Management
Title source: ruleDescription
The Simple User Registration plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3. This is due to insufficient restrictions on user meta values that can be supplied during registration. This makes it possible for unauthenticated attackers to register as an administrator.
Exploits (5)
github
WORKING POC
4 stars
by ctkqiang · gopoc
https://github.com/ctkqiang/CVE-Exploits/tree/main/CVE-2025-4334
github
WORKING POC
by Boshe99 · pythonpoc
https://github.com/Boshe99/CVE-Exploits/tree/main/CVE-2025-4334
Nuclei Templates (1)
Simple User Registration <= 6.3 - Unauthenticated Privilege Escalation
CRITICALVERIFIEDby pussycat0x
Shodan:
http.component:"wordpress" && http.html:"/wp-content/plugins/simple-user-registration/"
References (3)
Scores
CVSS v3
9.8
EPSS
0.3410
EPSS Percentile
97.0%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-269
Status
published
Products (2)
najeebmedia/simple_user_registration
< 6.3
nmedia/Simple User Registration
< 6.3
Published
Jun 26, 2025
Tracked Since
Feb 18, 2026