Impact
An IDOR flaw in the User Registration & Membership WordPress plugin allows any authenticated user with the Subscriber role or higher to cancel a pending email change that belongs to any other user, including administrators. The plugin does not confirm that the account whose email change is being cancelled matches the requester, which permits the attacker to manipulate another user’s pending email change. This can disrupt account recovery processes and expose the target user to further phishing or unintended account changes.
Affected Systems
WordPress sites running the User Registration & Membership plugin prior to version 5.2.5 are affected. All users using any earlier release of the plugin are at risk; the vulnerability exists in every release up to, but not including, 5.2.5.
Risk and Exploitability
The vulnerability can be exploited by an attacker with a legitimate Subscriber or higher account. Because no additional authentication is required beyond normal user privileges, it can be triggered from the user’s browser or through automated requests using the user’s credentials. No public exploit is currently listed in the KEV catalog, but the lack of access control is a high‑severity flaw. The EPSS score is not available, making it unclear how many users are targeted, but the fact that the flaw allows an attacker to cancel any user's pending email change suggests a potentially wide impact. The flaw is rated as a severe security issue requiring prompt remediation.
OpenCVE Enrichment