Impact
The User Registration & Membership WordPress plugin versions prior to 5.2.8 fails to verify the capability of the user making a membership purchase and neglects to validate the payment method or the plan submitted. As a result, any authenticated user—such as a subscriber—can purchase a paid plan and be granted the WordPress role tied to that plan without actually completing payment. If the site owner has mapped a paid plan to a privileged role, this flaw permits the attacker to obtain administrator privileges, compromising the integrity and confidentiality of the site.
Affected Systems
WordPress sites that employ the User Registration & Membership plugin with a version earlier than 5..8 are affected. The vulnerability applies to all installations of this plugin before the specified release, regardless of vendor details.
Risk and Exploitability
The vulnerability can be exploited by any authenticated user through the normal membership purchase flow, with no requirement for special network access or unauthenticated.5, indicating a high severity. The EPSS score is < 1%, indicating a very low but nonzero exploitation probability. The vulnerability is not listed in the CISA KEV catalog, yet the risk remains significant due to the potential for privilege escalation.
OpenCVE Enrichment