CVE-2026-80071
moderateAuthor-to-Admin Privilege Escalation in User Registration & Membership Plugin < 5.2.8
The User Registration & Membership WordPress plugin before 5.2.8 does not properly restrict who may author a membership plan, nor does it validate the plan a user attaches to their own account — a privilege-management flaw (CWE-269). An authenticated attacker with Author-level access or above can create or attach a membership plan that grants an arbitrary role, escalating their own account to Administrator. Successful exploitation effectively yields full site takeover, since an administrator can install plugins, modify all content, and access all site data. All sites running a version before 5.2.8 are affected, with multi-user sites where non-administrators hold authoring roles at greatest risk. No public proof of concept exists, the CVE is not in CISA's KEV catalog, and no exploitation in the wild has been reported.
What to do: Update to User Registration & Membership 5.2.8 or later as soon as possible. Audit your user list for unexplained Administrator accounts or role changes, and review any membership plans created or edited by non-administrator users. Until patched, restrict plan-authoring and publishing capabilities to trusted users and monitor audit logs for suspicious role assignments.
| WPEverest User Registration & Membership (WordPress plugin) | All versions before 5.2.8 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The User Registration & Membership WordPress plugin before 5.2.8 does not properly restrict who may author a membership plan or validate the plan a user attaches to their own account, allowing authenticated users with Author-level access and above to assign themselves an arbitrary role and escalate their privileges to Administrator.
- Ecosystems
- WordPress
- Weakness
- CWE-269
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.