CVE-2026-84756
moderateSubscriber Privilege Escalation in WCFM Membership WordPress Plugin
CVE-2026-84756 is an incorrect privilege assignment flaw (CWE-266) in the WCFM Membership WordPress plugin that allows a user with the lowest authenticated role (subscriber) to elevate their privileges. It is triggered by sending a network request while holding a subscriber-level account, with no user interaction or special conditions required (CVSS 3.1: AV:N/AC:L/PR:L/UI:N). A successful attacker gains elevated privileges within the affected site, with a high integrity impact and low confidentiality impact. Only WordPress sites running WCFM Membership version 2.11.11 or earlier are affected. Exploitation status is quiet: there is no known in-the-wild exploitation, no public proof-of-concept, the flaw is not in CISA KEV, and EPSS puts 30-day exploitation probability at just 0.2% (12th percentile).
What to do: Update WCFM Membership to the latest patched release (anything above 2.11.11). Site owners who cannot patch immediately should audit subscriber accounts for unexpected role or capability changes and review logs for privilege-modifying requests, and administrators should confirm whether the plugin is actually enabled on their sites before prioritizing remediation.
| WC Marketplace (WCFM) WCFM Membership WordPress plugin | <= 2.11.11 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Subscriber Privilege Escalation in WCFM Membership <= 2.11.11 versions.
- Ecosystems
- WordPress
- Weakness
- CWE-266
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:H/A:N
In the news0 stories
No ingested article mentions this CVE yet.