SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-11961

HIGH · CVSS 8.1 EPSS 0.25%

Source: NVD + CISA KEV + EPSS · Published 2026-07-17 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The User Registration & Membership plugin for WordPress prior to version 5.2.3 is vulnerable due to insufficient validation of membership tiers during public registration, enabling unauthenticated users to register for any available membership tier, including potentially gaining administrator privileges. This flaw poses a significant risk to WordPress sites utilizing the affected plugin, as it can lead to unauthorized access and control over the site. Website administrators and security teams should prioritize updating to the latest version to mitigate this high-severity vulnerability.

CVE
CVE-2026-11961
Severity
HIGH
CVSS
8.1
EPSS
0.25%
WordPress

Original NVD Description

The User Registration & Membership WordPress plugin before 5.2.3 does not validate that the membership tier submitted during public registration is one of the tiers allowed by the registration form before assigning that tier's associated user role, allowing unauthenticated users to register into an arbitrary published membership tier and obtain its role — up to administrator when such a tier exists.