CVE-2026-86406
—Payment Bypass Privilege Escalation in User Registration & Membership Plugin < 5.2.8
The User Registration & Membership WordPress plugin before 5.2.8 does not check the capability of the user making a membership purchase and does not validate the payment method or the plan submitted with it, so any authenticated user — even a low-privileged subscriber — can claim a paid membership plan without paying. When a site owner has mapped a paid plan to a privileged WordPress role, this becomes privilege escalation, potentially granting full administrator access. The flaw (CWE-269, CVSS 3.1: 7.5 high) is triggered simply by submitting a crafted membership purchase request while logged in as any registered user. Affected sites are WordPress installations running the plugin below 5.2.8, particularly those that map purchasable plans to privileged roles. No public PoC is known, the CVE is not on the CISA KEV list, and there is no evidence of exploitation in the wild.
What to do: Update to User Registration & Membership 5.2.8 or later immediately. Review your membership-plan-to-role mappings and remove any that assign privileged roles (especially administrator) to purchasable plans. Audit users, role assignments, and payment records for accounts that received paid plans or role changes without a corresponding successful payment.
| User Registration & Membership (WordPress plugin) | < 5.2.8 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The User Registration & Membership WordPress plugin before 5.2.8 does not check the capability of the user making a membership purchase, and does not validate the payment method or the plan submitted with it, allowing any authenticated user such as a subscriber to be granted the WordPress role attached to a paid plan without paying for it. Where the site owner has mapped a plan to a privileged role, this leads to privilege escalation up to administrator.
- Ecosystems
- WordPress
- Weakness
- CWE-269
- Vector
- CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.