CyberRota Analysis
AI-GeneratedThe User Registration & Membership plugin for WordPress prior to version 5.2.8 is vulnerable due to inadequate checks on user capabilities and payment validation, allowing authenticated users to gain access to paid plans without proper payment. This flaw can lead to privilege escalation, potentially granting unauthorized users administrative rights if a plan is linked to a privileged role. WordPress site administrators using this plugin should prioritize updating to mitigate the risk of exploitation.
Original NVD Description
The User Registration & Membership WordPress plugin before 5.2.8 does not check the capability of the user making a membership purchase, and does not validate the payment method or the plan submitted with it, allowing any authenticated user such as a subscriber to be granted the WordPress role attached to a paid plan without paying for it. Where the site owner has mapped a plan to a privileged role, this leads to privilege escalation up to administrator.