Impact
The WordPress plugin User Registration & Membership fails to enforce the site's open‑registration setting when handling form submissions, allowing any visitor to create new accounts even when the administrator has disabled open registration. This provides attackers with an unverified entry point to create credentials and obtain access to the site, potentially leading to privilege escalation if the site grants elevated roles to newly registered users. The weakness is an improper access control failure.
Affected Systems
Any WordPress site running the User Registration & Membership plugin with a version earlier than 5.2.6. Users of earlier releases are susceptible to unauthenticated account creation regardless of the site’s registration settings.
Risk and Exploitability
The flaw is exploitable by any internet‑accessible visitor submitting the registration form while registration is disabled. No EPSS data are available and the vulnerability is not listed in CISA KEV, but the lack of authentication control elevates risk. Because an attacker can create arbitrary accounts, the potential impact on confidentiality, integrity, and availability is high, especially if higher‑privileged user roles are granted by default. The CVSS score is not provided, but the vulnerability should be treated with high severity.
OpenCVE Enrichment