Executive brief
The User Registration & Membership WordPress plugin allows any logged-in user (even basic subscribers) to gain higher WordPress roles without paying for a membership. Site administrators who have linked paid membership plans to administrator accounts are at serious risk of account takeover, allowing attackers to take full control of the WordPress site and access all customer data.
Technical details
The plugin fails to validate user capabilities and payment verification during membership purchase operations, resulting in a privilege escalation vulnerability. Any authenticated user can bypass payment validation and role-check logic to claim a WordPress role associated with a paid plan. The vulnerability exists in versions before 5.2.8 and is triggered through the membership purchase workflow; no network access or social engineering is required, only a valid user account at subscriber level or higher. A successful exploit grants the attacker all permissions of the assigned role, potentially including full site administrative access. The vulnerability has been patched in version 5.2.8.
Affected products
- WordPress User Registration & Membership before 5.2.8
Timeline
- 2026-09-11: disclosed
- 2026-09-13: patched: Version 5.2.8 released