| CVE-2025-39400 | WordPress User Registration plugin < 4.2.0 - Reflected Cross Site Scripting (XSS) vulnerability | wpeverest | User Registration | High | 7.1 | 2025-04-24 16:08:32 | Deep Dive |
| CVE-2025-2594 | User Registration & Membership < 4.1.3 - Authentication Bypass | Unknown | User Registration & Membership | 高危 | - | 2025-04-22 06:00:07 | Deep Dive |
| CVE-2025-3284 | User Registration & Membership PRO – Custom Registration Form, Login Form, and User Profile <= 5.1.3 - Cross-Site Request Forgery to User Deletion | WPEverest | User Registration PRO – Custom Registration Form, Login Form, and User Profile WordPress Plugin | Medium | 4.3 | 2025-04-19 02:22:33 | Deep Dive |
| CVE-2025-27319 | WordPress User List plugin <= 1.5.1 - Reflected Cross Site Scripting (XSS) vulnerability | ivan82 | User List | High | 7.1 | 2025-04-17 15:47:59 | Deep Dive |
| CVE-2025-32655 | WordPress Restrict User Registration plugin <= 1.0.1 - CSRF to Stored XSS vulnerability | DevriX | Restrict User Registration | High | 7.1 | 2025-04-17 15:47:03 | Deep Dive |
| CVE-2025-2314 | User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor <= 3.13.5 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode | cozmoslabs | User Profile Builder – Beautiful User Registration Forms, User Profiles & User Role Editor | Medium | 6.4 | 2025-04-16 01:45:02 | Deep Dive |
| CVE-2025-26906 | WordPress WP Delete User Accounts plugin <= 1.2.3 - Cross Site Scripting (XSS) vulnerability | Ren Ventura | WP Delete User Accounts | Medium | 6.5 | 2025-04-15 21:53:12 | Deep Dive |
| CVE-2025-30708 | Oracle E-Business Suite 安全漏洞 | Oracle Corporation | Oracle User Management | High | 7.5 | 2025-04-15 20:31:09 | Deep Dive |
| CVE-2025-2563 | User Registration & Membership < 4.1.2- Unauthenticated Privilege Escalation | Unknown | User Registration & Membership | - | - | 2025-04-14 06:00:10 | Deep Dive |
| CVE-2025-3282 | User Registration & Membership – Custom Registration Form, Login Form, and User Profile <= 4.1.3 - Insecure Direct Object Reference to Unauthenticated Membership Modification | wpeverest | User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder | Medium | 5.3 | 2025-04-12 06:37:18 | Deep Dive |
| CVE-2025-3292 | User Registration & Membership – Custom Registration Form, Login Form, and User Profile <= 4.1.3 - Insecure Direct Object Reference to Authenticated (Subscriber+) User Password Update | wpeverest | User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder | Medium | 4.3 | 2025-04-12 06:37:17 | Deep Dive |
| CVE-2025-31524 | WordPress WP User Profiles plugin <= 2.6.2 - Privilege Escalation vulnerability | John James Jacoby | WP User Profiles | High | 8.8 | 2025-04-10 08:09:41 | Deep Dive |
| CVE-2025-3489 | Nababur Simple-User-Management-System register.php cross site scripting | Nababur | Simple-User-Management-System | Medium | 4.3 | 2025-04-10 03:00:16 | Deep Dive |
| CVE-2025-32612 | WordPress User Session Synchronizer plugin <= 1.4.0 - CSRF to Stored XSS vulnerability | rafasashi | User Session Synchronizer | High | 7.1 | 2025-04-09 16:09:29 | Deep Dive |
| CVE-2025-32679 | WordPress User Registration Using Contact Form 7 plugin <= 2.4 - Cross Site Request Forgery (CSRF) vulnerability | ZealousWeb | User Registration Using Contact Form 7 | Medium | 5.4 | 2025-04-09 16:09:14 | Deep Dive |
| CVE-2025-3064 | WPFront User Role Editor <= 4.2.1 - Cross-Site Request Forgery to Privilege Escalation via whitelist_options Function | syammohanm | WPFront User Role Editor | High | 8.8 | 2025-04-08 08:22:10 | Deep Dive |
| CVE-2025-2836 | RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login <= 6.0.4.3 - Authenticated (Subscriber+) Stored Cross-Site Scripting | metagauss | RegistrationMagic – Custom Registration Forms, User Registration, Payment, and User Login | Medium | 6.4 | 2025-04-04 05:22:45 | Deep Dive |
| CVE-2025-2874 | User Submitted Posts <= 20241026 - Authenticated (Admin+) Stored Cross-Site Scripting | specialk | User Submitted Posts – Enable Users to Submit Posts from the Front End | Medium | 4.4 | 2025-04-03 07:21:22 | Deep Dive |
| CVE-2025-31455 | WordPress Limit Max IPs Per User plugin <= 1.5 - Reflected Cross Site Scripting (XSS) vulnerability | ralxz | Limit Max IPs Per User | High | 7.1 | 2025-04-01 20:58:11 | Deep Dive |
| CVE-2025-30899 | WordPress User Registration plugin <= 4.0.3 - Cross Site Scripting (XSS) vulnerability | wpeverest | User Registration | Medium | 5.9 | 2025-03-27 10:55:50 | Deep Dive |