๐Ÿ” CVE Alert

CVE-2026-86407

LOW 3.7

User Registration & Membership < 5.2.8 - Unauthenticated User Data Disclosure via Membership Thank You Page

CVSS Score
3.7
EPSS Score
0.0%
EPSS Percentile
0th

The User Registration & Membership WordPress plugin before 5.2.8 does not verify that the visitor requesting its membership confirmation page owns the account named in the request, nor that any registration or purchase has taken place, allowing unauthenticated users to retrieve another user's email address, profile fields, role and membership order details. Exploitation requires the site owner to have added a user smart tag to that page's configurable message, which the shipped default does not contain.

Vendor unknown
Product user registration & membership
Published Sep 13, 2026
Last Updated Sep 13, 2026
Stay Ahead of the Next One

Get instant alerts for unknown user registration & membership

Be the first to know when new low vulnerabilities affecting unknown user registration & membership are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / User Registration & Membership
5.0 < 5.2.8

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/2c9eb1fe-4e18-4fd0-9581-5672ffc4b598/

Credits

Karthik Ramakrishnan WPScan