SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-86406

HIGH · CVSS 7.5

Source: NVD + CISA KEV + EPSS · Published 2026-09-13 · Last synced 2026-09-13

CyberRota Analysis

AI-Generated

The User Registration & Membership plugin for WordPress prior to version 5.2.8 is vulnerable due to inadequate checks on user capabilities and payment validation, allowing authenticated users to gain access to paid plans without proper payment. This flaw can lead to privilege escalation, potentially granting unauthorized users administrative rights if a plan is linked to a privileged role. WordPress site administrators using this plugin should prioritize updating to mitigate the risk of exploitation.

CVE
CVE-2026-86406
Severity
HIGH
CVSS
7.5
EPSS
N/A
WordPress

Original NVD Description

The User Registration & Membership WordPress plugin before 5.2.8 does not check the capability of the user making a membership purchase, and does not validate the payment method or the plan submitted with it, allowing any authenticated user such as a subscriber to be granted the WordPress role attached to a paid plan without paying for it. Where the site owner has mapped a plan to a privileged role, this leads to privilege escalation up to administrator.