Junglewise Threat Intelligence

CVE-2026-4604: Klubraum Membership Request missing authorization in kr_mr_store_settings

CVE-2026-4604 · Severity: medium · CVSS 5.3 · Published 2026-07-29

Executive brief

The Klubraum Membership Request plugin for WordPress, which manages member sign-ups, contains a security flaw that allows unauthorized individuals to change its settings. An attacker could exploit this to replace the organization's API token or modify the text shown to prospective members. This effectively allows an outsider to hijack the connection between the website and the Klubraum service, potentially redirecting membership data or disrupting the registration process.

Technical details

The Klubraum Membership Request plugin for WordPress suffers from a missing authorization vulnerability (CWE-862) within the `kr_mr_store_settings()` function. This function lacks a proper capability check, allowing unauthenticated remote attackers to invoke it and modify plugin configurations. Specifically, an attacker can update the Klubraum API token and the introduction text displayed on the membership request widget. This vulnerability affects all versions up to and including 1.1.0. A patch has been released in the plugin's trunk/latest version to address the missing authorization check.

Affected products

  • Klubraum Klubraum Membership Request up to, and including, 1.1.0

Timeline

  • 2026-07-29: disclosed
  • 2026-07-29: advisory

References