CVE-2026-80071
7.2WordPress · User Registration & Membership
The User Registration & Membership plugin contains a privilege escalation flaw allowing authenticated users to assign themselves administrative roles.
Executive summary
A critical privilege escalation vulnerability in the User Registration & Membership plugin allows authenticated users to gain full administrative control over the WordPress site.
Vulnerability
The plugin fails to perform adequate capability checks when users assign or validate membership plans, allowing an authenticated user with Author-level access or higher to elevate their privileges to Administrator.
Business impact
Successful exploitation of this vulnerability results in a complete compromise of the WordPress installation, as attackers can gain full administrative privileges. This level of access enables the attacker to modify site content, exfiltrate sensitive user data, or execute arbitrary code on the underlying server, posing a significant risk to organizational integrity and data security. The CVSS score of 7.2 reflects the high impact on confidentiality, integrity, and availability.
Remediation
Immediate Action: Update the User Registration & Membership plugin to version 5.2.8 or later immediately.
Proactive Monitoring: Review user account activity logs for unauthorized privilege changes or the creation of new administrative accounts by existing non-administrative users.
Compensating Controls: If immediate updates are not feasible, consider deactivating the plugin or implementing a Web Application Firewall (WAF) rule to restrict access to membership configuration endpoints.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the severity of potential privilege escalation, administrators must prioritize patching this vulnerability to ensure the security of their WordPress environment. Applying the update to version 5.2.8 is the only definitive way to mitigate the risk of unauthorized administrative access.
More WordPress CVEs all →
History
CVE Brief tracked this CVE 1 day before it had a CVSS score.
- Disclosed CVE record published
- Collected by CVE Brief No CVSS score yet; tracked as early warning
- CVSS score assigned 7.2 (3.1)
- Analyst report written
- Published in the daily brief high section
Sources
Originally found and disclosed by Baikuya, with WPScan (coordinator), per the CVE Program record.