Description
The User Registration & Membership WordPress plugin before 5.2.5 does not verify that the account whose pending email change is being cancelled belongs to the user making the request, allowing authenticated users with Subscriber-level access and above to cancel any other user's in-progress email change, including an administrator's.
Published: 2026-08-28
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An IDOR flaw in the User Registration & Membership WordPress plugin allows any authenticated user with the Subscriber role or higher to cancel a pending email change that belongs to any other user, including administrators. The plugin does not confirm that the account whose email change is being cancelled matches the requester, which permits the attacker to manipulate another user’s pending email change. This can disrupt account recovery processes and expose the target user to further phishing or unintended account changes.

Affected Systems

WordPress sites running the User Registration & Membership plugin prior to version 5.2.5 are affected. All users using any earlier release of the plugin are at risk; the vulnerability exists in every release up to, but not including, 5.2.5.

Risk and Exploitability

The vulnerability can be exploited by an attacker with a legitimate Subscriber or higher account. Because no additional authentication is required beyond normal user privileges, it can be triggered from the user’s browser or through automated requests using the user’s credentials. No public exploit is currently listed in the KEV catalog, but the lack of access control is a high‑severity flaw. The EPSS score is not available, making it unclear how many users are targeted, but the fact that the flaw allows an attacker to cancel any user's pending email change suggests a potentially wide impact. The flaw is rated as a severe security issue requiring prompt remediation.

Generated by OpenCVE AI on August 28, 2026 at 08:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade the User Registration & Membership plugin to version 5.2.5 or later, which includes the fix for the IDOR issue.
  • Audit active user accounts for any canceled or pending email changes and verify that all legitimate changes have been handled.
  • Restrict the Subscriber role to only those capabilities that are necessary, and consider revoking or limiting access for accounts that do not need to manage user data.
  • If an immediate upgrade is not possible, temporarily disable the plugin to prevent unauthorized cancellations.

Generated by OpenCVE AI on August 28, 2026 at 08:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 28 Aug 2026 09:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-639

Fri, 28 Aug 2026 07:30:00 +0000

Type Values Removed Values Added
Description The User Registration & Membership WordPress plugin before 5.2.5 does not verify that the account whose pending email change is being cancelled belongs to the user making the request, allowing authenticated users with Subscriber-level access and above to cancel any other user's in-progress email change, including an administrator's.
Title User Registration & Membership < 5.2.5 - Subscriber+ Pending Email Change Cancellation via IDOR
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-28T06:00:17.343Z

Reserved: 2026-08-25T17:07:25.695Z

Link: CVE-2026-79995

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-28T08:16:42.337

Modified: 2026-08-28T08:16:42.337

Link: CVE-2026-79995

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-28T09:00:10Z

Weaknesses
  • CWE-639

    Authorization Bypass Through User-Controlled Key