Vulnerability in User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder — CVE-2026-86406
What to do now
Update User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder to 5.2.8 or later.
Affected versions
- 4.4.6 to 5.2.7 (inclusive)
Affected: User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder (plugin, user-registration)
What the vulnerability is
The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to Privilege Escalation in versions 4.4.6 through 5.2.7. This is due to insufficient restriction on the capabilities a user may grant themselves. This makes it possible for authenticated attackers, with subscriber-level access and above, to elevate their privileges beyond those intended for their role.