MEDIUM

CVE-2026-1869

2026-06-26 CVSS v3.1
CVSS
6.5

Description

The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to unauthorized modification of data due to missing validation checks in the confirm_payment() function in all versions up to, and including, 5.2.0. This makes it possible for unauthenticated attackers to bypass payment processing and activate paid memberships.

Summary dbcve.org

This WordPress membership plugin has a broken access control vulnerability in the confirm_payment() function. The function lacks proper validation of payment status and user authorization, allowing unauthenticated attackers to manipulate the payment confirmation process and activate paid memberships without actually completing payment.

Mitigation

Update the plugin to version 5.2.1 or later once available. Alternatively, disable the plugin or restrict access to payment-related endpoints at the web server level until a patch is applied.

Weakness (CWE)

CWE-862 Missing Authorization

EPSS Score

0.3%
Probability of exploitation in next 30 days
23th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE