module
WP User Registration and Membership Unauthenticated Privilege Escalation (CVE-2025-2563)
| Disclosed | Created |
|---|---|
| Mar 24, 2025 | May 14, 2025 |
Disclosed
Mar 24, 2025
Created
May 14, 2025
Description
Exploits CVE-2025-2563 in the WordPress User Registration & Membership plugin.
1) Registers a free-membership user via AJAX.
2) Elevates that user to administrator via the membership AJAX action.
3) Logs in, uploads & executes a PHP payload.
1) Registers a free-membership user via AJAX.
2) Elevates that user to administrator via the membership AJAX action.
3) Logs in, uploads & executes a PHP payload.
Authors
wesley (wcraft)
Valentin Lobstein
Valentin Lobstein
Platform
Linux,PHP,Unix,Windows
Architectures
php, cmd
References
Module Options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
Rapid7 Labs
2026 Global Threat Landscape Report
The predictive window has collapsed. Exploitation follows disclosure in days. See how attackers are accelerating and how to stay ahead.