ZeroHour

CVE-2026-84756

moderate

Subscriber Privilege Escalation in WCFM Membership WordPress Plugin

CVSS 3.1
7.1 high
EPSS
<1%p12
Published
()
Modified
AI analysis

CVE-2026-84756 is an incorrect privilege assignment flaw (CWE-266) in the WCFM Membership WordPress plugin that allows a user with the lowest authenticated role (subscriber) to elevate their privileges. It is triggered by sending a network request while holding a subscriber-level account, with no user interaction or special conditions required (CVSS 3.1: AV:N/AC:L/PR:L/UI:N). A successful attacker gains elevated privileges within the affected site, with a high integrity impact and low confidentiality impact. Only WordPress sites running WCFM Membership version 2.11.11 or earlier are affected. Exploitation status is quiet: there is no known in-the-wild exploitation, no public proof-of-concept, the flaw is not in CISA KEV, and EPSS puts 30-day exploitation probability at just 0.2% (12th percentile).

What to do: Update WCFM Membership to the latest patched release (anything above 2.11.11). Site owners who cannot patch immediately should audit subscriber accounts for unexpected role or capability changes and review logs for privilege-modifying requests, and administrators should confirm whether the plugin is actually enabled on their sites before prioritizing remediation.

Affected
WC Marketplace (WCFM) WCFM Membership WordPress plugin<= 2.11.11
Estimated exposure
moderate≈10,000–20,000 WordPress sites (plugin shows roughly 10k+ active installs on WordPress.org) — WCFM Membership is an add-on plugin for WCFM Marketplace whose WordPress.org active-install count has historically been on the order of 10,000+, so exposure is likely a few thousand to low tens of thousands of sites, concentrated in…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Subscriber Privilege Escalation in WCFM Membership <= 2.11.11 versions.

Ecosystems
WordPress
Weakness
CWE-266
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N

In the news

No ingested article mentions this CVE yet.