CVE-2026-86406: User Registration & Membership < 5.2.8 - Subscriber+ Privilege Escalation via Membership Purchase
The User Registration & Membership WordPress plugin before 5.2.8 does not check the capability of the user making a membership purchase, and does not validate the payment method or the plan submitted with it, allowing any authenticated user such as a subscriber to be granted the WordPress role attached to a paid plan without paying for it. Where the site owner has mapped a plan to a privileged role, this leads to privilege escalation up to administrator.
Affected Software
Event History
Frequently Asked Questions
Who can exploit this issue?
Any authenticated WordPress user can exploit it, including a user with only the Subscriber role. The attacker must be able to submit a membership purchase request to the affected plugin.
When does this become an administrator-level compromise?
Administrator-level escalation is possible when the site owner has mapped a membership plan to the WordPress Administrator role. More generally, an attacker can obtain whichever WordPress role is attached to a submitted paid plan.
Does the attacker need to complete a legitimate payment?
No. The affected plugin does not validate the submitted payment method or plan, allowing an authenticated user to obtain the role associated with a paid plan without paying.
Which installations are affected?
Versions of User Registration & Membership before 5.2.8 are affected. Exposure depends on the plugin being used for membership purchases and on the roles mapped to its plans.