CVE-2026-16736: User Registration & Membership < 5.2.6 - Unauthenticated Account Creation While Registration Disabled
The User Registration & Membership WordPress plugin before 5.2.6 does not enforce the site's registration-disabled setting when processing registration-form submissions, allowing unauthenticated users to create new accounts even when the administrator has turned off open registration.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/User Registration & Membershipto a version that resolves this vulnerability.Fixed in 5.2.6 - Configuration
Ensure the site’s registration-disabled/open registration setting is turned off (registration disabled) so registration-form submissions are rejected when open registration is disabled.
WordPress registration-disabled (open registration) = enabled only if intended; set to disabled when you want to prevent unauthenticated account creation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-16736?
The severity of CVE-2026-16736 is rated at 54, indicating a moderate risk vulnerability.
How do I fix CVE-2026-16736?
To fix CVE-2026-16736, update the User Registration & Membership plugin to version 5.2.6 or higher.
What systems are affected by CVE-2026-16736?
CVE-2026-16736 affects the User Registration & Membership plugin for WordPress versions prior to 5.2.6.
What type of vulnerability is CVE-2026-16736?
CVE-2026-16736 is an unauthenticated account creation vulnerability that allows unauthorized users to create accounts.
What are the potential impacts of CVE-2026-16736?
The potential impacts of CVE-2026-16736 include unauthorized account creation and potential abuse of user functionalities.