SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-11963

HIGH · CVSS 8.1 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-07-13 · Last synced 2026-08-12

CyberRota Analysis

AI-Generated

The User Registration & Membership plugin for WordPress versions prior to 5.2.2 is vulnerable due to a lack of authorization checks during membership upgrades, enabling any authenticated user to alter another user's role and membership tier. This flaw poses a significant risk as it can lead to unauthorized privilege escalation within the WordPress environment. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate potential exploitation.

CVE
CVE-2026-11963
Severity
HIGH
CVSS
8.1
EPSS
0.20%
WordPress

Original NVD Description

The User Registration & Membership WordPress plugin before 5.2.2 does not perform an authorization check on a membership-upgrade action and derives the user to modify from a caller-supplied identifier instead of the current user, allowing any authenticated user such as a subscriber to change another user's WordPress role and membership tier.