Description
Unauthenticated Broken Authentication in User Registration & Membership Pro <= 5.4.5 versions.
Published: 2026-08-20
Score: 9.8 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an unauthenticated broken authentication flaw that allows an attacker to create or assume a valid admin account in the WordPress User Registration & Membership Pro plugin. If exploited, the attacker could gain full control of the WordPress installation, granting them the ability to modify content, install additional malicious plugins, or exfiltrate data. The weakness is classified as CWE-288, which focuses on improper authentication or authorization controls.

Affected Systems

The flaw is present in all releases of the WPEverest User Registration & Membership Pro plugin up to and including version 5.4.5. WordPress sites that have installed any of these affected versions are at risk, regardless of whether the sites use the plugin in a typical user registration workflow or a more privileged configuration.

Risk and Exploitability

The model CVSS score of 9.8 indicates a critical impact rating. No EPSS score is available, so the probability of exploitation cannot be quantified, but the high CVSS suggests that the vulnerability is easy to exploit once the attack vector is identified. The plugin is not currently listed in the CISA KEV catalog. The likely attack vector is through the plugin’s authentication workflow, which accepts unverified input and creates or modifies a user account without proper authentication checks.

Generated by OpenCVE AI on August 20, 2026 at 21:16 UTC.

Remediation

Vendor Solution

Update the WordPress User Registration & Membership Pro Plugin to the latest available version (at least 5.4.6).


OpenCVE Recommended Actions

  • Update the User Registration & Membership Pro plugin to version 5.4.6 or later.
  • If an immediate update is not feasible, revoke all existing admin credentials, reset passwords for all users, and enforce a policy of unique, strong passwords.
  • Actively monitor the site's authentication logs for suspicious account creation or modification events to detect any attempted exploitation.

Generated by OpenCVE AI on August 20, 2026 at 21:16 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 20 Aug 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 20 Aug 2026 12:15:00 +0000

Type Values Removed Values Added
Description Unauthenticated Broken Authentication in User Registration & Membership Pro <= 5.4.5 versions.
Title WordPress User Registration & Membership Pro plugin <= 5.4.5 - Account Takeover vulnerability
Weaknesses CWE-288
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-20T16:27:27.512Z

Reserved: 2026-08-14T10:15:59.205Z

Link: CVE-2026-74001

cve-icon Vulnrichment

Updated: 2026-08-20T16:19:13.704Z

cve-icon NVD

Status : Deferred

Published: 2026-08-20T12:16:36.940

Modified: 2026-08-20T17:19:41.650

Link: CVE-2026-74001

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-20T21:30:05Z

Weaknesses
  • CWE-288

    Authentication Bypass Using an Alternate Path or Channel