Description
The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to unauthorized modification of data due to missing validation checks in the confirm_payment() function in all versions up to, and including, 5.2.0. This makes it possible for unauthenticated attackers to bypass payment processing and activate paid memberships.
Published: 2026-06-26
Score: 6.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated attacker can exploit the User Registration & Membership plugin by sending a request to the confirm_payment() endpoint, which lacks proper authorization checks. This flaw allows the attacker to change payment status and activate paid memberships without completing the actual payment transaction. The weakness is classified as CWE-862, Missing Authorization, and can lead to unauthorized access to premium content, loss of revenue, and user data exposure due to elevated privileges.

Affected Systems

The vulnerability affects the WordPress plugin "User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder" developed by WPEverest. All released versions up to and including 5.2.0 are impacted. Sites running WordPress with this plugin and relying on its paid membership features are susceptible.

Risk and Exploitability

The CVSS score of 6.5 classifies the flaw as medium severity. No EPSS data is available, and the issue is not listed in the CISA KEV catalog. The likely attack vector is an unauthenticated HTTP request to the confirm_payment endpoint, enabling attackers to bypass payment processing entirely. As the flaw does not require user credentials, any web‑accessible site using the affected plugin is at risk. The absence of exploit data suggests the vulnerability is not yet widely exploited, but the potential impact warrants immediate attention.

Generated by OpenCVE AI on June 26, 2026 at 09:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the User Registration & Membership plugin to the newest available version, which includes the missing authorization check in confirm_payment().
  • If updating the plugin is not possible, restrict or block access to the confirm_payment() endpoint using a web application firewall or server‑level rule so that only authenticated users can reach it.
  • Modify the plugin’s membership settings to ensure that only authorized roles can activate paid memberships, reducing the risk of accidental or malicious activation.

Generated by OpenCVE AI on June 26, 2026 at 09:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 26 Jun 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 26 Jun 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Wpeverest
Wpeverest user Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder
Vendors & Products Wordpress
Wordpress wordpress
Wpeverest
Wpeverest user Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder

Fri, 26 Jun 2026 08:45:00 +0000

Type Values Removed Values Added
Description The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to unauthorized modification of data due to missing validation checks in the confirm_payment() function in all versions up to, and including, 5.2.0. This makes it possible for unauthenticated attackers to bypass payment processing and activate paid memberships.
Title User Registration & Membership <= 5.2.0 - Missing Authorization to Unauthenticated Payment Bypass
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 6.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N'}


Subscriptions

Wordpress Wordpress
Wpeverest User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-06-26T12:09:41.534Z

Reserved: 2026-02-03T22:55:07.904Z

Link: CVE-2026-1869

cve-icon Vulnrichment

Updated: 2026-06-26T12:09:36.259Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-26T13:00:13Z

Weaknesses