PT-2026-60722 · WordPress · User Registration & Membership
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
User Registration & Membership WordPress plugin versions prior to 5.2.3
Description
An issue exists where the plugin fails to validate if the membership tier submitted during public registration is among the tiers permitted by the registration form. This allows unauthenticated users to register for any published membership tier and acquire the associated user role, which could potentially grant administrator privileges if such a tier is available.
Recommendations
Update the User Registration & Membership WordPress plugin to version 5.2.3 or later.
Exploit
Fix
DoS
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
User Registration & Membership