Impact
The User Registration & Membership WordPress plugin before version 5.2.2 fails to enforce an authorization check when processing a membership‑upgrade request. The plugin accepts a user identifier supplied by the caller and uses it to determine which user’s role and membership tier to modify, instead of automatically using the current user’s ID. This flaw allows any authenticated user—including subscribers with no elevated privileges—to change the WordPress role and membership level of any other user, effectively granting the attacker higher permissions.
Affected Systems
All WordPress sites that use the User Registration & Membership plugin with a version earlier than 5.2.2 are affected. The plugin appears under the WordPress listing name "User Registration & Membership". No hardware or platform restrictions are noted.
Risk and Exploitability
The vulnerability requires only that the attacker be authenticated to the WordPress installation; no further privileges are needed. Once logged in, the attacker can manipulate the user ID sent to the membership‑upgrade endpoint and alter another user’s role and membership tier. The CVSS score of 8.1 indicates high severity, while the EPSS score of less than 1% shows a very low but non‑zero exploitation probability. The issue is not listed in the CISA KEV catalog. Despite the low exploitation probability, the clear attack path and potential for full privilege escalation present a significant risk to the confidentiality, integrity, and overall security of the site.
OpenCVE Enrichment