ZeroHour

CVE-2026-80071

moderate

Author-to-Admin Privilege Escalation in User Registration & Membership Plugin < 5.2.8

CVSS 3.1
7.2 high
EPSS
Published
()
Modified
AI analysis

The User Registration & Membership WordPress plugin before 5.2.8 does not properly restrict who may author a membership plan, nor does it validate the plan a user attaches to their own account — a privilege-management flaw (CWE-269). An authenticated attacker with Author-level access or above can create or attach a membership plan that grants an arbitrary role, escalating their own account to Administrator. Successful exploitation effectively yields full site takeover, since an administrator can install plugins, modify all content, and access all site data. All sites running a version before 5.2.8 are affected, with multi-user sites where non-administrators hold authoring roles at greatest risk. No public proof of concept exists, the CVE is not in CISA's KEV catalog, and no exploitation in the wild has been reported.

What to do: Update to User Registration & Membership 5.2.8 or later as soon as possible. Audit your user list for unexplained Administrator accounts or role changes, and review any membership plans created or edited by non-administrator users. Until patched, restrict plan-authoring and publishing capabilities to trusted users and monitor audit logs for suspicious role assignments.

Affected
WPEverest User Registration & Membership (WordPress plugin)All versions before 5.2.8
Estimated exposure
moderateOn the order of tens of thousands of sites (≈10,000–100,000) — Estimated from the typical active-install base of the WPEverest user-registration/membership plugin family on WordPress.org; no exact install count was provided in the source data, so this is an order-of-magnitude estimate only.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The User Registration & Membership WordPress plugin before 5.2.8 does not properly restrict who may author a membership plan or validate the plan a user attaches to their own account, allowing authenticated users with Author-level access and above to assign themselves an arbitrary role and escalate their privileges to Administrator.

Ecosystems
WordPress
Weakness
CWE-269
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.