CVE-2026-79996
N/A
N/A
Summary
The User Registration & Membership WordPress plugin before 5.2.6 does not perform a capability check when saving its login settings, allowing authenticated users who have been granted a User Registration & Membership WordPress plugin before 5.2.6 management capability but not full administrator access to change arbitrary site options and escalate their privileges to administrator.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | User Registration & Membership | 0 < 5.2.6 | affected |
Weaknesses
- CWE-269 Improper Privilege Management
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.