Stored Cross-Site Scripting in User Registration Plugin for WordPress
CVE-2025-6831
6.4MEDIUM
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 22 July 2025
What is CVE-2025-6831?
The User Registration plugin for WordPress is susceptible to Stored Cross-Site Scripting (XSS) via the plugin's urcr_restrict shortcode. This vulnerability arises from inadequate input sanitization and output escaping on user-supplied attributes, impacting all versions up to and including 4.2.4. Authenticated attackers with contributor-level access or higher could exploit this flaw to inject arbitrary web scripts into pages that execute whenever another user accesses those injected pages.
Affected Version(s)
User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin * <= 4.2.4