← Back to CVE search

CVE-2026-79996

User Registration & Membership

Description

The User Registration & Membership WordPress plugin before 5.2.6 does not perform a capability check when saving its login settings, allowing authenticated users who have been granted a User Registration & Membership WordPress plugin before 5.2.6 management capability but not full administrator access to change arbitrary site options and escalate their privileges to administrator.

EPSS 0.14200000000000002%Risk 0
View source
Published
2026-08-28 08:16:42
Affected versions
<5.2.6
Type
Web application
Last modified
2026-08-28 08:16:42
Vector
Pending