CVE-2025-4334
CRITICAL NUCLEINajeebmedia Simple User Registration - Improper Privilege Management
Title source: ruleDescription
The Simple User Registration plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 6.3. This is due to insufficient restrictions on user meta values that can be supplied during registration. This makes it possible for unauthenticated attackers to register as an administrator.
Exploits (5)
github
WORKING POC
4 stars
by ctkqiang · gopoc
https://github.com/ctkqiang/CVE-Exploits/tree/main/CVE-2025-4334
github
WORKING POC
by Boshe99 · pythonpoc
https://github.com/Boshe99/CVE-Exploits/tree/main/CVE-2025-4334
Nuclei Templates (1)
Simple User Registration <= 6.3 - Unauthenticated Privilege Escalation
CRITICALVERIFIEDby pussycat0x
Shodan:
http.component:"wordpress" && http.html:"/wp-content/plugins/simple-user-registration/"
Scores
CVSS v3
9.8
EPSS
0.2808
EPSS Percentile
96.4%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Classification
CWE
CWE-269
Status
published
Affected Products (1)
najeebmedia/simple_user_registration
< 6.3
Timeline
Published
Jun 26, 2025
Tracked Since
Feb 18, 2026