SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-79996

HIGH · CVSS 7.2 EPSS 0.32%

Source: NVD + CISA KEV + EPSS · Published 2026-08-28 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

The User Registration & Membership plugin for WordPress versions prior to 5.2.6 is vulnerable due to a lack of capability checks when saving login settings, enabling authenticated users with specific management capabilities to modify site options and escalate their privileges to administrator. This vulnerability poses a significant risk to site integrity and security, particularly for installations where user roles are not strictly managed. WordPress administrators and security teams should prioritize updating to the latest version to mitigate potential exploitation.

CVE
CVE-2026-79996
Severity
HIGH
CVSS
7.2
EPSS
0.32%
WordPress

Original NVD Description

The User Registration & Membership WordPress plugin before 5.2.6 does not perform a capability check when saving its login settings, allowing authenticated users who have been granted a User Registration & Membership WordPress plugin before 5.2.6 management capability but not full administrator access to change arbitrary site options and escalate their privileges to administrator.