CVE-2026-79995: User Registration & Membership < 5.2.5 - Subscriber+ Pending Email Change Cancellation via IDOR
The User Registration & Membership WordPress plugin before 5.2.5 does not verify that the account whose pending email change is being cancelled belongs to the user making the request, allowing authenticated users with Subscriber-level access and above to cancel any other user's in-progress email change, including an administrator's.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Any authenticated WordPress user with Subscriber-level access or higher can exploit it. The attacker does not need to control the account whose pending email change is targeted.
What actions can an attacker perform?
An attacker can cancel another user's in-progress email address change, including a pending change for an administrator account. The issue affects the cancellation action because ownership of the targeted pending change is not verified.
Which plugin versions are affected?
Versions of User Registration & Membership before 5.2.5 are affected.