Impact
An IDOR flaw in the User Registration & Membership WordPress plugin allows any authenticated user with the Subscriber role or higher to cancel a pending email change that belongs to any other user, including administrators. The plugin does not confirm that the account whose email change is being cancelled matches the requester, which permits the attacker to manipulate another user’s pending email change. This can disrupt account recovery processes and expose the target user to further phishing or unintended account changes.
Affected Systems
WordPress sites running the User Registration & Membership plugin prior to version 5.2.5 are affected. All users using any earlier release of the plugin are at risk; the vulnerability exists in every release up to, but not including, 5.2.5.
Risk and Exploitability
The vulnerability can be exploited by an attacker with a legitimate Subscriber or higher account. Because no additional authentication is required beyond normal user privileges, it can be triggered from the user’s browser or through automated requests using the user’s credentials. No public exploit is currently listed in the KEV catalog, and the CVSS score of 4.3 classifies it as a low‑severity flaw. The EPSS score is < 1%, indicating a very low but non‑zero exploitation probability. While the impact is limited due to the low severity and exploitation likelihood, the flaw still allows arbitrary cancellation of other users’ pending email changes and should be remediated to prevent potential account disruption.
OpenCVE Enrichment