Vulnerability in User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder — CVE-2026-80071
What to do now
Update User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder to 5.2.8 or later.
Affected versions
- Everything before 5.2.8
Affected: User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder (plugin, user-registration)
What the vulnerability is
The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to Privilege Escalation in all versions up to 5.2.8. This is due to insufficient restriction on the capabilities a user may grant themselves. This makes it possible for authenticated attackers, with author-level access and above, to elevate their privileges beyond those intended for their role.