CVE-2026-74001: WordPress User Registration & Membership Pro plugin <= 5.4.5 - Account Takeover vulnerability
Published Aug 20, 2026
·Updated
Unauthenticated Broken Authentication in User Registration & Membership Pro <= 5.4.5 versions.
Affected Software
1 affected component
WordPress User Registration & Membership Pro plugin<=5.4.5
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress User Registration & Membership Proto a version that resolves this vulnerability.Fixed in 5.4.6
Event History
Aug 20, 2026
CVE Published
via MITRE·12:07 PM
Data Sourced
via MITRE·12:07 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What access does an attacker need to exploit this issue?
No authentication or prior privileges are required. The vector is network-accessible and requires low attack complexity with no user interaction.
2
What is the potential impact if exploitation succeeds?
The vulnerability can lead to account takeover and is rated critical with high impact to confidentiality, integrity, and availability.
3
Which plugin versions are affected?
User Registration & Membership Pro versions 5.4.5 and earlier are affected.