PT-2026-57375 · WordPress · Members – Membership & User Role Editor Plugin

·

CVE-2026-12426

·

Published

2026-07-11

·

Updated

2026-07-11

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Members – Membership & User Role Editor Plugin versions prior to 3.2.23
Description An issue exists that allows unauthenticated attackers to expose sensitive information through the members filter protected posts for rest function. This flaw enables the determination of the existence and exact count of access-restricted posts. Furthermore, attackers can utilize per-page pagination as a boolean oracle—a technique where a binary response (true/false) is used to deduce hidden data—to infer keywords and content within these restricted posts.
Recommendations Update the plugin to a version newer than 3.2.22.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-12426

Affected Products

Members – Membership & User Role Editor Plugin