Executive brief
The User Registration & Membership WordPress plugin allows authenticated users with author-level permissions or higher to assign themselves administrator privileges by exploiting insufficient validation of membership plan assignments. An attacker with basic author account access could gain full administrative control of a WordPress site, enabling account takeover, content manipulation, malware installation, and complete site compromise.
Technical details
This is a privilege escalation vulnerability stemming from improper access controls and insufficient validation in the membership plan authorization logic. The vulnerable component fails to restrict which users can author membership plans and does not validate the role assignment when a user attaches a plan to their own account. An authenticated attacker with Author-level access or above can craft a request to assign themselves an arbitrary administrative role, bypassing authorization checks. No special network conditions or user interaction are required beyond initial authentication. The vulnerability affects versions before 5.2.8, which contains the fix.
Affected products
- Automattic User Registration & Membership before 5.2.8
Timeline
- 2026-09-13: disclosed: CVE-2026-80071 published
- 2026-05-??: patched: Fixed in version 5.2.8