CVE-2025-39400: Wpeverest User Registration & Membership

Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wpeverest User Registration user-registration allows Reflected XSS.This issue affects User Registration: from n/a through < 4.2.0.

Affected products

  • Wpeverest User Registration & Membership: before 4.2.0 (fixed in 4.2.0); before 5.2.0 (fixed in 5.2.0)

Published 2025-04-24. Last modified 2026-06-17.