CyberRota Analysis
AI-GeneratedThe User Registration & Membership plugin for WordPress versions prior to 5.2.3 is vulnerable due to a lack of capability checks for unauthenticated users, enabling attackers to delete payment-pending user accounts by supplying arbitrary user identifiers. This vulnerability poses a risk of account manipulation and potential financial loss for users. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.
Original NVD Description
The User Registration & Membership WordPress plugin before 5.2.3 does not perform a capability check for unauthenticated callers on one of its membership payment actions and acts on a caller-supplied user identifier, allowing unauthenticated attackers to delete recently-registered, payment-pending user accounts.