← Back to CVE search

CVE-2026-11961

User Registration & Membership

Description

The User Registration & Membership WordPress plugin before 5.2.3 does not validate that the membership tier submitted during public registration is one of the tiers allowed by the registration form before assigning that tier-s associated user role, allowing unauthenticated users to register into an arbitrary published membership tier and obtain its role — up to administrator when such a tier exists.

CVSS 8.1EPSS 0.247%Risk 0.83
View source
Published
2026-07-17 07:16:37
Affected versions
<5.2.3
Type
Web application
Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H