Unrated severityNVD Advisory· Published Jul 2, 2026· Updated Jul 2, 2026
User Registration & Membership < 5.2.0 - Unauthenticated Paid Membership Bypass
CVE-2026-11965
Description
The User Registration & Membership WordPress plugin before 5.2.0 does not enforce payment completion before activating a paid membership subscription, allowing unauthenticated users (after self-registering an account through the open registration flow) to obtain an active subscription on any paid plan without paying and access the gated content.
Affected products
1- Range: <5.2.0
Patches
Vulnerability mechanics
References
1- wpscan.com/vulnerability/49f4c59e-5931-405d-8518-244531bbc889/mitreexploitvdb-entrytechnical-description
News mentions
0No linked articles in our index yet.