Description
The User Registration & Membership WordPress plugin before 5.2.8 does not properly restrict who may author a membership plan or validate the plan a user attaches to their own account, allowing authenticated users with Author-level access and above to assign themselves an arbitrary role and escalate their privileges to Administrator.
Published: 2026-09-13
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation to Administrator
Action: Immediate Patch
AI Analysis

Impact

The WordPress "User Registration & Membership" plugin before version 5.2.8 fails to enforce role checks when creating or updating a membership plan. As a result, any authenticated user with Author or higher privileges can set an arbitrary role for themselves, including Administrator. The flaw directly raises the user’s privileges to full site administration. This is a classic privilege escalation vulnerability, rated with a CVSS score of 7.2, which could allow an attacker to compromise confidentiality, integrity and availability of the entire WordPress installation.

Affected Systems

WordPress installations running the "User Registration & Membership" plugin before version 5.2.8 are affected. The plugin’s earlier releases lack the necessary checks to or validate the plan attached to a user’s own account. An authenticated Author or higher user can set an arbitrary role for themselves, including Administrator, granting full control over the site.

Risk and Exploitability

The exploit requires authenticated access with Author privileges; no additional external available, and the vulnerability is not listed in the CISA KEV catalog. The lack of widespread public exploitation suggests a low to moderate exploitation probability, but the severity of a successful attack—granting Administrator rights—makes this a high‑risk vulnerability for any site that hosts the affected plugin. The risk is compounded by the fact that the attack vector is only limited by existing authenticated author users,.

Generated by OpenCVE AI on September 15, 2026 at 17:25 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Update the "User Registration & Membership" plugin to version 5.2.8 or later.
  • Reconfigure role capabilities so that only Administrators can create or edit membership plans and assign roles.
  • Disable or strictly restrict the role assignment functionality for Author‑level users until the patch is applied.

Generated by OpenCVE AI on September 15, 2026 at 17:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 04:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Sun, 13 Sep 2026 12:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Sun, 13 Sep 2026 11:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Sun, 13 Sep 2026 06:15:00 +0000

Type Values Removed Values Added
Description The User Registration & Membership WordPress plugin before 5.2.8 does not properly restrict who may author a membership plan or validate the plan a user attaches to their own account, allowing authenticated users with Author-level access and above to assign themselves an arbitrary role and escalate their privileges to Administrator.
Title User Registration & Membership < 5.2.8 - Author+ Privilege Escalation to Administrator
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-13T10:45:53.169Z

Reserved: 2026-08-25T18:22:58.616Z

Link: CVE-2026-80071

cve-icon Vulnrichment

Updated: 2026-09-13T10:42:29.475Z

cve-icon NVD

Status : Deferred

Published: 2026-09-13T06:16:24.947

Modified: 2026-09-14T21:10:17.423

Link: CVE-2026-80071

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-15T17:30:10Z

Weaknesses
  • CWE-269

    Improper Privilege Management