SEPTEMBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-11966

MEDIUM · CVSS 5.3 EPSS 0.20%

Source: NVD + CISA KEV + EPSS · Published 2026-07-17 · Last synced 2026-08-16

CyberRota Analysis

AI-Generated

The User Registration & Membership plugin for WordPress versions prior to 5.2.3 is vulnerable due to a lack of capability checks for unauthenticated users, enabling attackers to delete payment-pending user accounts by supplying arbitrary user identifiers. This vulnerability poses a risk of account manipulation and potential financial loss for users. WordPress site administrators using this plugin should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-11966
Severity
MEDIUM
CVSS
5.3
EPSS
0.20%
WordPress

Original NVD Description

The User Registration & Membership WordPress plugin before 5.2.3 does not perform a capability check for unauthenticated callers on one of its membership payment actions and acts on a caller-supplied user identifier, allowing unauthenticated attackers to delete recently-registered, payment-pending user accounts.