Unknown User Registration & Membership

6 known vulnerabilities in Unknown User Registration & Membership, with patch priority, exploit likelihood and the news covering them.

Latest vulnerabilities

  • CVE-2026-86407 CVSS 3.7 low The User Registration & Membership WordPress plugin before 5.2.8 does not verify that the visitor requesting its membership confirmation…
  • CVE-2026-86406 CVSS 7.5 high The User Registration & Membership WordPress plugin before 5.2.8 does not check the capability of the user making a membership purchase…
  • CVE-2026-80072 CVSS 4.7 medium The User Registration & Membership WordPress plugin before 5.2.8 does not validate the destination of a post-login redirect before…
  • CVE-2026-80071 CVSS 7.2 high The User Registration & Membership WordPress plugin before 5.2.8 does not properly restrict who may author a membership plan or validate…
  • CVE-2026-79996 CVSS 7.2 high The User Registration & Membership WordPress plugin before 5.2.6 does not perform a capability check when saving its login settings…
  • CVE-2026-79995 CVSS 4.3 medium The User Registration & Membership WordPress plugin before 5.2.5 does not verify that the account whose pending email change is being…