ZeroHour

CVE-2026-79996

large

Privilege Escalation in WordPress User Registration & Membership Plugin

CVSS 3.1
7.2 high
EPSS
<1%p24
Published
()
Modified
AI analysis

The User Registration & Membership WordPress plugin before 5.2.6 does not perform a proper capability check when saving its login settings, allowing changes to arbitrary WordPress options by users who hold only the plugin's delegated management capability. An authenticated user who has been granted the User Registration management capability (but is not a full administrator) can trigger a settings save that writes arbitrary site options. By modifying options such as the default new-user role, the attacker can elevate their own account to administrator, gaining full control of the site. Sites are affected if they run an affected version and administrators have delegated the plugin's management capability to non-administrator users; sites using the plugin only with default administrator access are exposed to a much lesser degree. No public proof-of-concept is known, the issue is not in CISA KEV, and EPSS estimates only a 0.3% chance of exploitation within 30 days, so no in-the-wild exploitation is currently known.

What to do: Update the User Registration & Membership plugin to version 5.2.6 or later. As an interim mitigation, ensure only full administrators are granted the plugin's User Registration management capability. Review recently modified site options (e.g., default role settings) and user role assignments for signs of unauthorized privilege changes.

Affected
WPEverest User Registration & Membership (WordPress plugin)< 5.2.6
Estimated exposure
largeon the order of ~100,000 sites (plugin has roughly 100,000 active WordPress installs); the subset delegating the plugin-management capability to non-admins is… — Estimate is based on the plugin's publicly reported active-install count on WordPress.org of approximately 100,000, reduced to sites that actually grant the User Registration management capability to non-administrator users, a subset that…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The User Registration & Membership WordPress plugin before 5.2.6 does not perform a capability check when saving its login settings, allowing authenticated users who have been granted a User Registration & Membership WordPress plugin before 5.2.6 management capability but not full administrator access to change arbitrary site options and escalate their privileges to administrator.

Ecosystems
WordPress
Weakness
CWE-269
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.