Junglewise Threat Intelligence

CVE-2026-1869: WPEverest User Registration & Membership payment bypass

CVE-2026-1869 · Severity: medium · CVSS 6.5 · Published 2026-06-26

Technologies: WPEverest User Registration. Vendors: WPEverest.

Executive brief

A popular WordPress plugin used for managing user registrations and paid memberships contains a security flaw that allows users to bypass payment requirements. By exploiting this issue, an unauthorized individual can activate premium membership features without actually paying for a subscription. This can lead to direct revenue loss and unauthorized access to restricted site content.

Technical details

The User Registration & Membership plugin for WordPress is vulnerable to missing authorization due to insufficient validation checks in the confirm_payment() function. This flaw allows unauthenticated remote attackers to manipulate the payment confirmation process. By sending a crafted request to the vulnerable function, an attacker can trick the system into marking a transaction as successful without a valid payment. This results in the unauthorized activation of paid membership tiers and access to restricted content. The issue affects all versions up to and including 5.2.0.

Affected products

  • WPEverest User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder <= 5.2.0

Timeline

  • 2026-06-26: disclosed
  • 2026-06-26: advisory

References

Related threats