CVE-2026-86407
User Registration & Membership < 5.2.8 - Unauthenticated User Data Disclosure via Membership Thank You Page
CVSS Score
3.7
EPSS Score
0.0%
EPSS Percentile
0th
The User Registration & Membership WordPress plugin before 5.2.8 does not verify that the visitor requesting its membership confirmation page owns the account named in the request, nor that any registration or purchase has taken place, allowing unauthenticated users to retrieve another user's email address, profile fields, role and membership order details. Exploitation requires the site owner to have added a user smart tag to that page's configurable message, which the shipped default does not contain.
| Vendor | unknown |
| Product | user registration & membership |
| Published | Sep 13, 2026 |
| Last Updated | Sep 13, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown user registration & membership
Be the first to know when new low vulnerabilities affecting unknown user registration & membership are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / User Registration & Membership
5.0 < 5.2.8
References
Credits
Karthik Ramakrishnan WPScan