Impact
Versions before 5.2.0 lack verification that a payment has been completed before activating a paid membership subscription. An attacker can register an account through the public registration form, choose any paid plan, and obtain an active subscription without completing the payment. The result is immediate access to premium or gated content that is intended only for paid members, leading to unauthorized revenue loss and potential content disclosure. This flaw represents a breach of access control (undermines authentication safeguards, CWE‑306).
Affected Systems
All WordPress sites that have the "User Registration & Membership" plugin installed with a version earlier than 5.2.0 are vulnerable. The vulnerability applies to any deployment where the plugin’s registration and subscription processes are active.
Risk and Exploitability
The likely attack vector is the publicly reachable registration flow; it is inferred that an attacker needs no special credentials. The CVSS score of 6.5 indicates moderate severity. The EPSS score of less than 1% suggests that exploitation attempts are unlikely but still possible, and the vulnerability is not listed in the CISA KEV catalog. Given these metrics, the risk to affected sites is moderate, but the potential impact of unauthorized access and revenue loss warrants timely remediation.
OpenCVE Enrichment