PT-2026-52683 · WordPress · User Registration & Membership

·

CVE-2026-1869

·

Published

2026-06-26

·

Updated

2026-06-26

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N
Name of the Vulnerable Software and Affected Versions User Registration & Membership versions prior to 5.2.1
Description Missing validation checks in the confirm payment() function allow unauthenticated attackers to perform unauthorized modification of data. This flaw enables the bypass of payment processing to activate paid memberships.
Recommendations Update the plugin to a version later than 5.2.0. As a temporary workaround, consider restricting access to the confirm payment() function until the update is applied.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-1869

Affected Products

User Registration & Membership