Description
The User Registration & Membership WordPress plugin before 5.2.6 does not enforce the site's registration-disabled setting when processing registration-form submissions, allowing unauthenticated users to create new accounts even when the administrator has turned off open registration.
Published: 2026-08-05
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The WordPress plugin User Registration & Membership fails to enforce the site's open‑registration setting when handling form submissions, allowing any visitor to create new accounts even when the administrator has disabled open registration. This provides attackers with an unverified entry point to create credentials and obtain access to the site, potentially leading to privilege escalation if the site grants elevated roles to newly registered users. The weakness is an improper access control failure.

Affected Systems

Any WordPress site running the User Registration & Membership plugin with a version earlier than 5.2.6. Users of earlier releases are susceptible to unauthenticated account creation regardless of the site’s registration settings.

Risk and Exploitability

The flaw is exploitable by any internet‑accessible visitor submitting the registration form while registration is disabled. No EPSS data are available and the vulnerability is not listed in CISA KEV, but the lack of authentication control elevates risk. Because an attacker can create arbitrary accounts, the potential impact on confidentiality, integrity, and availability is high, especially if higher‑privileged user roles are granted by default. The CVSS score is not provided, but the vulnerability should be treated with high severity.

Generated by OpenCVE AI on August 5, 2026 at 07:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the User Registration & Membership plugin to version 5.2.6 or later, which enforces registration settings.
  • If an upgrade is not yet possible, temporarily disable the plugin or block access to its registration endpoint with a firewall or security plugin.
  • Review newly created accounts and adjust user roles to prevent privilege escalation, and monitor registration logs for suspicious activity.

Generated by OpenCVE AI on August 5, 2026 at 07:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 05 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Description The User Registration & Membership WordPress plugin before 5.2.6 does not enforce the site's registration-disabled setting when processing registration-form submissions, allowing unauthenticated users to create new accounts even when the administrator has turned off open registration.
Title User Registration & Membership < 5.2.6 - Unauthenticated Account Creation While Registration Disabled
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-05T06:00:10.288Z

Reserved: 2026-07-23T07:49:11.677Z

Link: CVE-2026-16736

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T07:30:16Z

Weaknesses