Executive brief
The User Registration & Membership WordPress plugin fails to verify that a visitor requesting the membership confirmation page actually owns the account or made a purchase. This allows unauthenticated attackers to retrieve other users' email addresses, profile information, roles, and order details by simply guessing usernames. While the plugin's default configuration is safe, sites that customize the confirmation message to display user information (using smart tags) become vulnerable to this data exposure.
Technical details
This is an authentication bypass and information disclosure vulnerability (CWE-200) in the membership confirmation page component. The vulnerable thank-you page fails to validate that the requesting user owns the account or has completed a transaction associated with the username parameter. An unauthenticated attacker can craft HTTP requests with arbitrary username parameters to retrieve user data if smart tags like {{user_email}} or {{membership_plan_details}} are present in the page's configurable message. The attack requires no authentication, no session cookies, and no user interaction—just HTTP GET requests with username parameters. The vulnerability is fixed in version 5.2.8.
Affected products
- wpuserregistration User Registration & Membership before 5.2.8
Timeline
- 2026-09-11: disclosed
- 2026-09-13: patched: Version 5.2.8