Impact
The WordPress "User Registration & Membership" plugin before version 5.2.8 fails to enforce role checks when creating or updating a membership plan. As a result, any authenticated user with Author or higher privileges can set an arbitrary role for themselves, including Administrator. The flaw directly raises the user’s privileges to full site administration. This is a classic privilege escalation vulnerability, rated with a CVSS score of 7.2, which could allow an attacker to compromise confidentiality, integrity and availability of the entire WordPress installation.
Affected Systems
WordPress installations running the "User Registration & Membership" plugin before version 5.2.8 are affected. The plugin’s earlier releases lack the necessary checks to or validate the plan attached to a user’s own account. An authenticated Author or higher user can set an arbitrary role for themselves, including Administrator, granting full control over the site.
Risk and Exploitability
The exploit requires authenticated access with Author privileges; no additional external available, and the vulnerability is not listed in the CISA KEV catalog. The lack of widespread public exploitation suggests a low to moderate exploitation probability, but the severity of a successful attack—granting Administrator rights—makes this a high‑risk vulnerability for any site that hosts the affected plugin. The risk is compounded by the fact that the attack vector is only limited by existing authenticated author users,.
OpenCVE Enrichment