CVE-2026-1869
Received Received - Intake
Unauthorized Membership Activation in WordPress User Registration Plugin

Publication date: 2026-06-26

Last updated on: 2026-06-26

Assigner: Wordfence

Description
The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to unauthorized modification of data due to missing validation checks in the confirm_payment() function in all versions up to, and including, 5.2.0. This makes it possible for unauthenticated attackers to bypass payment processing and activate paid memberships.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-26
Last Modified
2026-06-26
Generated
2026-06-26
AI Q&A
2026-06-26
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
wp_user_registration plugin to 5.2.0 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability exists in the User Registration & Membership plugin for WordPress, specifically in the confirm_payment() function. Due to missing validation checks, unauthenticated attackers can bypass the payment processing mechanism.

As a result, attackers can activate paid memberships without actually completing the payment process.

Impact Analysis

The vulnerability allows unauthorized users to activate paid memberships without paying, which can lead to financial loss for the site owner.

It also undermines the integrity of the membership system, potentially allowing access to restricted content or services without proper authorization.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-1869. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart