CVE-2026-79996: User Registration & Membership < 5.2.6 - Authenticated Privilege Escalation via Login Settings
The User Registration & Membership WordPress plugin before 5.2.6 does not perform a capability check when saving its login settings, allowing authenticated users who have been granted a User Registration & Membership WordPress plugin before 5.2.6 management capability but not full administrator access to change arbitrary site options and escalate their privileges to administrator.
Affected Software
Event History
Frequently Asked Questions
Which users are realistically able to exploit this issue?
An attacker must already be authenticated and have been granted the plugin's management capability. Full WordPress administrator access is not required.
What access does successful exploitation provide?
The affected user can change arbitrary site options through the plugin's login settings and use that access to escalate to WordPress administrator privileges.
Which versions are affected?
Versions of User Registration & Membership before 5.2.6 are affected.