CVE-2026-12497
7.5WordPress Plugin Author · Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content
An improper privilege management vulnerability in the Paid Membership Plugin for WordPress before 4.16.18 allows unauthenticated visitors to register with elevated roles.
Executive summary
An improper privilege management vulnerability in the Paid Membership Plugin for WordPress affects versions prior to 4.16.18, allowing unauthenticated attackers to register accounts with elevated privileges.
Vulnerability
This flaw is an improper privilege management vulnerability stemming from inconsistent role restriction enforcement and the absence of a nonce on the public registration handler, allowing unauthenticated users to register with roles like Editor or Author.
Business impact
A successful exploitation of this vulnerability allows unauthenticated attackers to gain unauthorized access to administrative or editorial capabilities, potentially leading to unauthorized data exposure, content manipulation, or site takeover. Based on a CVSS score of 7.5, this issue is classified as high severity, reflecting the potential for complete confidentiality compromise of user data and unauthorized privilege escalation.
Remediation
Immediate Action: Update the Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content to version 4.16.18 or later.
Proactive Monitoring: Monitor user registration logs for unusual account creation patterns, particularly unexpected accounts created with elevated roles such as Editor or Author.
Compensating Controls: Implement Web Application Firewalls (WAF) rules to restrict registration attempts or limit access to front-end registration endpoints if immediate patching is not feasible.
Exploitation status
Public Exploit Available: No (As of the latest assessment, no confirmed weaponized exploit or public proof-of-concept exists).
Analyst recommendation
Given the high severity score and the potential for unauthorized privilege escalation, administrators must prioritize addressing this vulnerability immediately. Apply the official vendor update to version 4.16.18 or higher without delay to secure the registration workflow and prevent unauthorized account creation.
More WordPress Plugin Author CVEs
Sources
Originally found and disclosed by Muni Nitish Kumar Yaddala, with WPScan (coordinator), per the CVE Program record.