The Simple User Registration plugin ≤ 6.3 is vulnerable to privilege escalation. It lacks proper restrictions on user meta values during registration. Unauthenticated attackers can exploit this to register as administrators.
id: CVE-2025-4334
info:
name: Simple User Registration <= 6.3 - Unauthenticated Privilege Escalat
...