CVE-2026-84756: WordPress WCFM Membership plugin <= 2.11.11 - Privilege Escalation vulnerability
Published Sep 3, 2026
·Updated
Subscriber Privilege Escalation in WCFM Membership <= 2.11.11 versions.
Affected Software
1 affected component
WordPress/WCFM Membership<=2.11.11
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WCFM Membership pluginto a version that resolves this vulnerability.Fixed in 2.12.0
Event History
Sep 3, 2026
CVE Published
via MITRE·04:31 PM
Data Sourced
via MITRE·04:31 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
Does exploitation require an existing account?
Yes. The CVSS vector indicates low privileges are required, so an attacker needs an authenticated account with limited permissions, such as a subscriber-level account.
2
Can the issue be exploited remotely or does it require user interaction?
The vulnerability is network-accessible, has low attack complexity, and does not require user interaction according to the supplied CVSS vector.
3
What is the likely security impact if exploited?
The rating indicates high impact to integrity and low impact to confidentiality. Availability impact is listed as none.