CVE-2026-79996
largePrivilege Escalation in WordPress User Registration & Membership Plugin
The User Registration & Membership WordPress plugin before 5.2.6 does not perform a proper capability check when saving its login settings, allowing changes to arbitrary WordPress options by users who hold only the plugin's delegated management capability. An authenticated user who has been granted the User Registration management capability (but is not a full administrator) can trigger a settings save that writes arbitrary site options. By modifying options such as the default new-user role, the attacker can elevate their own account to administrator, gaining full control of the site. Sites are affected if they run an affected version and administrators have delegated the plugin's management capability to non-administrator users; sites using the plugin only with default administrator access are exposed to a much lesser degree. No public proof-of-concept is known, the issue is not in CISA KEV, and EPSS estimates only a 0.3% chance of exploitation within 30 days, so no in-the-wild exploitation is currently known.
What to do: Update the User Registration & Membership plugin to version 5.2.6 or later. As an interim mitigation, ensure only full administrators are granted the plugin's User Registration management capability. Review recently modified site options (e.g., default role settings) and user role assignments for signs of unauthorized privilege changes.
| WPEverest User Registration & Membership (WordPress plugin) | < 5.2.6 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The User Registration & Membership WordPress plugin before 5.2.6 does not perform a capability check when saving its login settings, allowing authenticated users who have been granted a User Registration & Membership WordPress plugin before 5.2.6 management capability but not full administrator access to change arbitrary site options and escalate their privileges to administrator.
- Ecosystems
- WordPress
- Weakness
- CWE-269
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.