Executive brief
User Registration & Membership Pro is a WordPress plugin that handles user account registration and membership management. An unauthenticated attacker can bypass the login system and gain unauthorized access to user accounts without knowing passwords, potentially allowing account takeover and unauthorized access to customer data or administrative functions.
Technical details
This is a broken authentication vulnerability (CWE-287) in the User Registration & Membership Pro WordPress plugin affecting versions up to 5.4.5. The vulnerability allows unauthenticated attackers to bypass the login mechanism and authenticate as arbitrary users, likely through a flaw in the authentication validation logic or session handling. No network authentication is required—the attack can be performed remotely by any internet-connected attacker. The vulnerability enables complete account takeover and unauthorized system access. Version 5.4.6 and later contain the fix.
Affected products
- Unknown User Registration & Membership Pro <=5.4.5
Timeline
- 2026-08-20: disclosed
- 2026-08-19: patched: Version 5.4.6 released