Description
The User Registration & Membership WordPress plugin before 5.2.6 does not enforce the site's registration-disabled setting when processing registration-form submissions, allowing unauthenticated users to create new accounts even when the administrator has turned off open registration.
Published: 2026-08-05
Score: 7.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The WordPress plugin User Registration & Membership fails to enforce the site's open-registration setting when handling form submissions, allowing any visitor to create new accounts even when the administrator has disabled open registration. This provides attackers with an unverified entry point to create credentials and obtain access to the site, potentially leading to privilege escalation if the site grants elevated roles to newly registered users. The weakness is an improper access control failure.

Affected Systems

Any WordPress site running the User Registration & Membership plugin with a version earlier than 5.2.6. Users of earlier releases are susceptible to unauthenticated account creation regardless of the site's registration settings.

Risk and Exploitability

The flaw is exploitable by any internet-accessible visitor submitting the registration form while registration is disabled. The EPSS score is < 1%, indicating a very low but nonzero exploitation probability, and the vulnerability is not listed in CISA KEV. Despite the low exploitation probability, the lack of authentication control elevates risk. Because an attacker can create arbitrary accounts, the potential impact on confidentiality, integrity, and availability is high, especially if higher-privileged user roles are granted by default. The CVSS score is 7.5, indicating a high severity level.

Generated by OpenCVE AI on August 5, 2026 at 17:53 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the User Registration & Membership plugin to version 5.2.6 or later, which enforces registration settings.
  • If an upgrade is not yet possible, temporarily disable the plugin or block access to its registration endpoint with a firewall or security plugin.
  • Review newly created accounts and adjust user roles to prevent privilege escalation, and monitor registration logs for suspicious activity.

Generated by OpenCVE AI on August 5, 2026 at 17:53 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 16:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Wed, 05 Aug 2026 06:30:00 +0000

Type Values Removed Values Added
Description The User Registration & Membership WordPress plugin before 5.2.6 does not enforce the site's registration-disabled setting when processing registration-form submissions, allowing unauthenticated users to create new accounts even when the administrator has turned off open registration.
Title User Registration & Membership < 5.2.6 - Unauthenticated Account Creation While Registration Disabled
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-05T15:18:10.214Z

Reserved: 2026-07-23T07:49:11.677Z

Link: CVE-2026-16736

cve-icon Vulnrichment

Updated: 2026-08-05T15:18:06.756Z

cve-icon NVD

Status : Received

Published: 2026-08-05T07:16:36.433

Modified: 2026-08-05T16:16:52.977

Link: CVE-2026-16736

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T18:00:10Z

Weaknesses