CVE advisoryCRITICAL
CVE-2025-4334
WordPress Simple User Registration Privilege Escalation
Halo Surface Signal: 5 out of 5 — more likely to be public-facing.
This vulnerability in the Simple User Registration plugin allows unauthenticated attackers to gain administrator privileges on WordPress sites due to insufficient restrictions on user meta values during registration. This could lead to full site compromise and unauthorized access to data.