CVE-2025-67956

WordPress User Registration plugin <= 4.4.6 - Broken Access Control vulnerability

Missing Authorization vulnerability in wpeverest User Registration user-registration allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects User Registration: from n/a through <= 4.4.6.


We have discovered 5,262 live websites that are affected by CVE-2025-67956.

Run a Free Instant Scan




Affected Software

Product  User Registration
Category Wordpress Plugins
Vulnerable Domains5,262 live websites (68% of User Registration install base)
Vulnerable Versions
  • from 0 through 4.4.6
Vulnerable Versions Count125 versions ( 94% of all versions)



Details

  • Published - Jan 22, 2026
  • Updated - Jan 29, 2026

Credits

  • Mdr | Patchstack Bug Bounty Program (finder)

Website Distribution by Country

Number of websites using CVE-2025-67956
United States1,395 websites



Italy463 websites
Germany400 websites
France240 websites
GB235 websites
Spain192 websites
Brazil143 websites
Cyprus126 websites
India125 websites
Canada107 websites

Website Distribution by TLD

Number of websites using CVE-2025-67956
.com2,139 websites
.org350 websites
.it331 websites
.de137 websites
.com.br133 websites
.co.uk114 websites
.net105 websites
.com.au94 websites
.nl89 websites
.ru82 websites

Vulnerable Versions

Vulnerable versions are highlighted in red

Websites affected by CVE-2025-67956

Top websites that are affected by CVE-2025-67956. Please click on the "Contact us" link to get more information.
DomainCountryRankContacts
****************.com France**,***
*********.com United States**,***
************.com United States**,***
********.de Germany**,***
************.**.il Israel**,***
***.**.th Thailand**,***
********.com United States***,***
**********.org France***,***
****************.com France***,***
****************.org GB***,***
See full domain list

FAQ

A total of 5,262 websites have been identified as vulnerable to CVE-2025-67956, based on global website indexing conducted by WebTechSurvey.
The User Registration is affected by the CVE-2025-67956 vulnerability.
User Registration versions up to and including 4.4.6 are vulnerable to CVE-2025-67956.