Junglewise Threat Intelligence

CVE-2026-11964: User Registration & Membership auth bypass in PayPal webhook handler

CVE-2026-11964 · Severity: info · CVSS 6.5 · Published 2026-07-13

Vendors: Unknown.

Executive brief

The User Registration & Membership plugin for WordPress, which manages paid subscriptions and user accounts, fails to verify the authenticity of payment notifications from providers like PayPal. This allows an attacker to trick the website into thinking a payment was successful when it was not. As a result, unauthorized users can gain access to premium membership content and services without actually paying for them, leading to direct revenue loss.

Technical details

The vulnerability is an authentication bypass in the PayPal webhook handler of the User Registration & Membership plugin. The plugin fails to validate the cryptographic signatures (e.g., PAYPAL-TRANSMISSION-SIG) of incoming webhook POST requests to the '/user-registration/paypal-webhook' REST route. An attacker can register for a paid plan to obtain the necessary 'custom_id' parameters and then send a crafted JSON payload to the webhook endpoint. Because the plugin processes these unverified notifications as legitimate, it updates the order status to 'completed' and activates the subscription. This issue is fixed in version 5.2.2.

Affected products

  • Unknown User Registration & Membership < 5.2.2

Timeline

  • 2026-06-22: disclosed: Publicly published by WPScan and researchers.
  • 2026-07-13: advisory: NVD published the CVE record.

References