CVE-2025-2594 | User Registration & Membership Plugin up to 4.1.2 on WordPress confirm_payment improper authentication
A vulnerability classified as critical has been found in User Registration & Membership Plugin up to 4.1.2 on WordPress. Affected is the function confirm_payment. The manipulation leads to improper authentication.
This vulnerability is traded as CVE-2025-2594. It is possible to launch the attack remotely. There is no exploit available.