Description
Subscriber Privilege Escalation in WCFM Membership <= 2.11.11 versions.
Published: 2026-09-03
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Update plugin
AI Analysis

Impact

A flaw in the WC Lovers WCFM Membership plugin for WordPress allows a subscriber user to elevate their privileges. The vulnerability results from improper enforcement of role checks and can lead to an attacker gaining administrative access.

Affected Systems

The issue affects installations of the WC Lovers WCFM Membership plugin up to and including version 2.11.11. If a WordPress site uses this plugin and has subscriber accounts, it is potentially vulnerable. Sites running newer versions, such as 2.12.0 or later, are not affected.

Risk and Exploitability

The CVSS score of 7.1 indicates high severity, and while an EPSS score is not available, the lack of data suggests a potential but unknown exploitation likelihood. The vulnerability is not currently listed in CISA’s KEV catalog. The likely attack vector is that an authenticated subscriber could trigger role assignment logic to elevate privileges; this exploits CWE‑266, an Improper Privilege Management flaw.

Generated by OpenCVE AI on September 3, 2026 at 20:41 UTC.

Remediation

Vendor Solution

Update the WordPress WCFM Membership plugin to the latest available version (at least 2.12.0).


OpenCVE Recommended Actions

  • Apply the vendor patch: update the WCFM Membership plugin to version 2.12.0 or newer.
  • Temporarily disable the plugin or restrict subscriber access until the upgrade is complete to reduce the window of exploitation.
  • Audit current user role assignments and remove any unintended elevated privileges that may have been granted before the update.

Generated by OpenCVE AI on September 3, 2026 at 20:41 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 07 Sep 2026 12:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 03 Sep 2026 18:15:00 +0000

Type Values Removed Values Added
First Time appeared Wclovers
Wclovers wcfm Membership
Wordpress
Wordpress wordpress
Vendors & Products Wclovers
Wclovers wcfm Membership
Wordpress
Wordpress wordpress

Thu, 03 Sep 2026 16:45:00 +0000

Type Values Removed Values Added
Description Subscriber Privilege Escalation in WCFM Membership <= 2.11.11 versions.
Title WordPress WCFM Membership plugin <= 2.11.11 - Privilege Escalation vulnerability
Weaknesses CWE-266
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N'}


Subscriptions

Wclovers Wcfm Membership
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-09-07T11:17:29.055Z

Reserved: 2026-09-02T09:57:31.409Z

Link: CVE-2026-84756

cve-icon Vulnrichment

Updated: 2026-09-07T11:16:49.571Z

cve-icon NVD

Status : Deferred

Published: 2026-09-03T17:17:26.117

Modified: 2026-09-07T12:17:20.423

Link: CVE-2026-84756

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-03T20:45:05Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment