PT-2026-57632 · WordPress · User Registration & Membership
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
User Registration & Membership WordPress plugin versions prior to 5.2.2
Description
The plugin fails to verify the authenticity of incoming payment-provider webhook notifications. This allows unauthenticated attackers to forge a payment-approved event, enabling the activation of a paid membership subscription without completing an actual payment.
Recommendations
Update the User Registration & Membership WordPress plugin to version 5.2.2 or later.
Exploit
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
User Registration & Membership