CVE-2026-86406
Received Received - Intake

Privilege Escalation in User Registration & Membership WordPress Plugin

Vulnerability report for CVE-2026-86406, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-13

Last updated on: 2026-09-13

Assigner: WPScan

Description

The User Registration & Membership WordPress plugin before 5.2.8 does not check the capability of the user making a membership purchase, and does not validate the payment method or the plan submitted with it, allowing any authenticated user such as a subscriber to be granted the WordPress role attached to a paid plan without paying for it. Where the site owner has mapped a plan to a privileged role, this leads to privilege escalation up to administrator.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-13
Last Modified
2026-09-13
Generated
2026-09-13
AI Q&A
2026-09-13
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wpengine user_registration_and_membership to 5.2.8 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the WordPress plugin User Registration & Membership before version 5.2.8. It allows any authenticated user, including subscribers, to escalate their privileges by purchasing a membership without proper validation. The plugin fails to check user capabilities, validate payment methods, or verify the submitted plan, enabling attackers to obtain a privileged WordPress role such as administrator if the site owner has mapped a paid plan to such a role.

Detection Guidance

Check the installed version of the User Registration & Membership plugin in WordPress. If it is below 5.2.8, the system is vulnerable. Use commands like 'wp plugin list' in WP-CLI or inspect the plugin files in the /wp-content/plugins/user-registration-and-membership/ directory for version details.

Impact Analysis

An attacker could exploit this to gain unauthorized administrative access to a WordPress site, potentially taking control of the site, stealing data, or installing malicious software. Even low-privilege users like subscribers could escalate to administrator if the site owner has assigned privileged roles to paid plans.

Compliance Impact

This vulnerability could lead to unauthorized privilege escalation, potentially granting attackers administrative access to a WordPress site. For GDPR, this may result in unauthorized access to personal data, violating principles of data protection and user consent. Under HIPAA, if the site handles protected health information, unauthorized access could compromise confidentiality requirements.

Mitigation Strategies

Update the User Registration & Membership plugin to version 5.2.8 or later immediately. If updating is not possible, consider disabling the plugin temporarily until a patch is applied. Review user roles and permissions to identify any unauthorized privilege escalations.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-86406. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart