SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-11964

CRITICAL · CVSS 9.1 EPSS 0.27%

Source: NVD + CISA KEV + EPSS · Published 2026-07-13 · Last synced 2026-08-12

CyberRota Analysis

AI-Generated

The User Registration & Membership plugin for WordPress versions prior to 5.2.2 is vulnerable due to a lack of verification for incoming payment-provider webhook notifications. This flaw allows unauthenticated attackers to simulate a payment-approved event, potentially granting unauthorized access to paid membership subscriptions without actual payment. WordPress site administrators using this plugin should prioritize immediate updates to mitigate the risk of exploitation.

CVE
CVE-2026-11964
Severity
CRITICAL
CVSS
9.1
EPSS
0.27%
WordPress

Original NVD Description

The User Registration & Membership WordPress plugin before 5.2.2 does not verify the authenticity of incoming payment-provider webhook notifications before acting on them, allowing unauthenticated attackers to forge a payment-approved event and activate a paid membership subscription without completing a real payment.