CVE-2026-62040
Received Received - Intake

Missing Authorization in Restrict User Access Membership Plugin

Vulnerability report for CVE-2026-62040, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: Patchstack

Description

Missing Authorization vulnerability in DEV Institute Restrict User Access – Membership Plugin with Force restrict-user-access allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Restrict User Access – Membership Plugin with Force: from n/a through 2.8.1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
DEV Institute Restrict User Access – Membership Plugin with Force 0

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-62040 is a Missing Authorization vulnerability in the WordPress plugin 'Restrict User Access – Membership Plugin with Force Plugin' versions up to 2.8.1. It allows unauthenticated users to access restricted pages or perform unauthorized actions due to incorrectly configured access control security levels.

Detection Guidance

Check if the WordPress plugin 'Restrict User Access – Membership Plugin with Force' is installed and verify its version. If it is version 2.8.1 or lower, the system is vulnerable. Inspect server logs for unauthorized access attempts or unusual user activity.

Impact Analysis

This vulnerability may allow unauthorized users to view sensitive data of other users or perform actions they should not have permission to do. However, its impact is considered low severity with a CVSS score of 5.3, and exploitation is unlikely due to limited impact.

Compliance Impact

This vulnerability could potentially lead to unauthorized access to sensitive user data, which may violate compliance requirements under regulations like GDPR or HIPAA if such data is exposed. However, the provided context does not explicitly detail specific compliance impacts or data types affected.

Mitigation Strategies

Disable the plugin immediately if possible. Update to the latest version if an official patch becomes available. Alternatively, seek assistance from a hosting provider or developer to apply mitigations. Monitor for suspicious activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-62040. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart