Impact
The User Registration & Membership plugin before version 5.2.0 fails to verify that a payment has been completed before enabling a paid membership subscription. As a result, anyone can self‑register through the public registration form, select a paid plan, and receive an active subscription without completing the payment. The flaw allows unauthenticated users to gain immediate and unfettered access to content that is intended solely for paying members, creating a direct revenue loss and the risk of premature exposure of premium material.
Affected Systems
All WordPress sites that have the User Registration & Membership plugin installed with a version earlier than 5.2.0. The vulnerability is triggered whenever the registration and subscription workflows are active, regardless of additional site configurations or other plugins that may be present.
Risk and Exploitability
The likely attack vector is the publicly reachable registration flow, with no need for prior authentication or special privileges. The CVSS score of 6.5 indicates a moderate severity that can affect confidentiality, integrity, and availability of the site’s premium content. The EPSS score of less than 1% suggests that exploitation attempts are rare but still feasible. Because the flaw is not listed in CISA KEV, it has not yet been widely reported in the wild, but the potential financial impact makes timely remediation advisable.
OpenCVE Enrichment