Executive brief
The User Registration & Membership WordPress plugin allows authenticated users with plugin management permissions to escalate their access to full administrator status without authorization. An attacker with limited plugin management rights can modify site-wide settings and gain unrestricted control over the WordPress installation, potentially compromising the entire website and customer data.
Technical details
The plugin fails to properly validate user capabilities when processing login settings updates, allowing privilege escalation through an insecure direct object reference (CWE-269). An authenticated attacker with User Registration & Membership management capability can change arbitrary site options via the plugin's settings endpoint without proper authorization checks. The vulnerability requires the attacker to already have some authenticated access with plugin management permissions, but allows them to bypass administrator-level checks and modify critical WordPress options. The vulnerability was patched in version 5.2.6.
Affected products
- WordPress User Registration & Membership before 5.2.6
Timeline
- 2026-08-26: disclosed
- 2026-08-26: patched: version 5.2.6