Executive brief
The User Registration & Membership plugin for WordPress, which manages paid subscriptions and user accounts, fails to verify the authenticity of payment notifications from providers like PayPal. This allows an attacker to trick the website into thinking a payment was successful when it was not. As a result, unauthorized users can gain access to premium membership content and services without actually paying for them, leading to direct revenue loss.
Technical details
The vulnerability is an authentication bypass in the PayPal webhook handler of the User Registration & Membership plugin. The plugin fails to validate the cryptographic signatures (e.g., PAYPAL-TRANSMISSION-SIG) of incoming webhook POST requests to the '/user-registration/paypal-webhook' REST route. An attacker can register for a paid plan to obtain the necessary 'custom_id' parameters and then send a crafted JSON payload to the webhook endpoint. Because the plugin processes these unverified notifications as legitimate, it updates the order status to 'completed' and activates the subscription. This issue is fixed in version 5.2.2.
Affected products
- Unknown User Registration & Membership < 5.2.2
Timeline
- 2026-06-22: disclosed: Publicly published by WPScan and researchers.
- 2026-07-13: advisory: NVD published the CVE record.