← Späť na vyhľadávanie CVE

CVE-2026-11961

User Registration & Membership

Popis

The User Registration & Membership WordPress plugin before 5.2.3 does not validate that the membership tier submitted during public registration is one of the tiers allowed by the registration form before assigning that tier-s associated user role, allowing unauthenticated users to register into an arbitrary published membership tier and obtain its role — up to administrator when such a tier exists.

CVSS 8.1EPSS 0.247%Riziko 0.83
Zobraziť zdroj
Zverejnené
2026-07-17 07:16:37
Dotknuté verzie
<5.2.3
Typ
Webová aplikácia
Vektor
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H