module
WP User Registration and Membership Unauthenticated Privilege Escalation (CVE-2025-2563)
Disclosed | Created |
---|---|
Mar 24, 2025 | May 14, 2025 |
Disclosed
Mar 24, 2025
Created
May 14, 2025
Description
Exploits CVE-2025-2563 in the WordPress User Registration & Membership plugin.
1) Registers a free-membership user via AJAX.
2) Elevates that user to administrator via the membership AJAX action.
3) Logs in, uploads & executes a PHP payload.
1) Registers a free-membership user via AJAX.
2) Elevates that user to administrator via the membership AJAX action.
3) Logs in, uploads & executes a PHP payload.
Authors
wesley (wcraft)
Valentin Lobstein
Valentin Lobstein
Platform
Linux,PHP,Unix,Windows
Architectures
php, cmd
References
Module Options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':

NEW
Explore Exposure Command
Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.