SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-79995

MEDIUM · CVSS 4.3 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-08-28 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The User Registration & Membership plugin for WordPress prior to version 5.2.5 is vulnerable due to inadequate verification of user permissions when canceling pending email changes. This flaw allows authenticated users with Subscriber-level access or higher to disrupt email change requests for any user, including administrators, potentially leading to account takeover or unauthorized access. WordPress site administrators and security teams should prioritize updating this plugin to mitigate the risk of abuse.

CVE
CVE-2026-79995
Severity
MEDIUM
CVSS
4.3
EPSS
0.18%
WordPress

Original NVD Description

The User Registration & Membership WordPress plugin before 5.2.5 does not verify that the account whose pending email change is being cancelled belongs to the user making the request, allowing authenticated users with Subscriber-level access and above to cancel any other user's in-progress email change, including an administrator's.