SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-86407

LOW · CVSS 3.7 Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-13 · Last synced 2026-09-13

CyberRota Analysis

AI-Generated

The User Registration & Membership plugin for WordPress prior to version 5.2.8 is vulnerable as it fails to authenticate users requesting access to the membership confirmation page, potentially exposing sensitive information such as email addresses and profile details of other users. While the severity is classified as low, site owners who have customized their confirmation messages to include user smart tags should prioritize updating to mitigate the risk of unauthorized data exposure. This vulnerability primarily affects WordPress site administrators and developers utilizing this plugin.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-86407
Severity
LOW
CVSS
3.7
EPSS
N/A
WordPress

Original NVD Description

The User Registration & Membership WordPress plugin before 5.2.8 does not verify that the visitor requesting its membership confirmation page owns the account named in the request, nor that any registration or purchase has taken place, allowing unauthenticated users to retrieve another user's email address, profile fields, role and membership order details. Exploitation requires the site owner to have added a user smart tag to that page's configurable message, which the shipped default does not contain.