๐Ÿ” CVE Alert

CVE-2026-80071

HIGH 7.2

User Registration & Membership < 5.2.8 - Author+ Privilege Escalation to Administrator

CVSS Score
7.2
EPSS Score
0.0%
EPSS Percentile
0th

The User Registration & Membership WordPress plugin before 5.2.8 does not properly restrict who may author a membership plan or validate the plan a user attaches to their own account, allowing authenticated users with Author-level access and above to assign themselves an arbitrary role and escalate their privileges to Administrator.

Vendor unknown
Product user registration & membership
Published Sep 13, 2026
Last Updated Sep 13, 2026
Stay Ahead of the Next One

Get instant alerts for unknown user registration & membership

Be the first to know when new high vulnerabilities affecting unknown user registration & membership are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / User Registration & Membership
0 < 5.2.8

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/a4fbdeea-0d3b-466b-b4b6-4c4db277cd1d/

Credits

Baikuya WPScan