CVE-2026-80072
Received Received - Intake

User Registration Plugin Post-Login Redirect Phishing Vulnerability

Vulnerability report for CVE-2026-80072, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-13

Last updated on: 2026-09-13

Assigner: WPScan

Description

The User Registration & Membership WordPress plugin before 5.2.8 does not validate the destination of a post-login redirect before redirecting, allowing unauthenticated attackers to redirect visitors to an arbitrary external URL, which can be abused for phishing.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-13
Last Modified
2026-09-13
Generated
2026-09-13
AI Q&A
2026-09-13
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wpengine user_registration_membership to 5.2.8 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an unauthenticated open redirect flaw in the User Registration & Membership WordPress plugin before version 5.2.8. It allows attackers to manipulate login redirect parameters to send users to arbitrary external websites, which could be used for phishing attacks.

Detection Guidance

Check the installed version of the User Registration & Membership plugin. If it is below 5.2.8, the system is vulnerable. Use WordPress admin panel or run a command like 'wp plugin list' in the WordPress directory to verify the version.

Impact Analysis

Unauthenticated attackers could trick users into visiting malicious websites via phishing links, potentially leading to credential theft, malware infections, or other security breaches. Users may unknowingly follow redirects to harmful sites.

Compliance Impact

This vulnerability could lead to data breaches or unauthorized access, violating GDPR's data protection requirements and HIPAA's security rules. Organizations may face fines or penalties for failing to protect user data.

Mitigation Strategies

Update the User Registration & Membership plugin to version 5.2.8 or later immediately. Disable the plugin temporarily if an update is not immediately available, and monitor for suspicious redirect activity in server logs.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-80072. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart