CVE-2026-80071: User Registration & Membership < 5.2.8 - Author+ Privilege Escalation to Administrator
The User Registration & Membership WordPress plugin before 5.2.8 does not properly restrict who may author a membership plan or validate the plan a user attaches to their own account, allowing authenticated users with Author-level access and above to assign themselves an arbitrary role and escalate their privileges to Administrator.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
wordpress/User Registration & Membershipto a version that resolves this vulnerability.Fixed in 5.2.8
Event History
Frequently Asked Questions
Which plugin versions require remediation?
User Registration & Membership versions before 5.2.8 are affected. Upgrade to version 5.2.8 or later.
Does exploitation require an existing account?
Yes. An attacker must be authenticated and have Author-level access or higher in WordPress.
What access can an attacker obtain after exploiting this issue?
The attacker can attach a membership plan to their own account that assigns an arbitrary role, including Administrator.