WordPress Plugin Vulnerabilities
User Registration & Membership < 5.2.8 - Subscriber+ Privilege Escalation via Membership Purchase
Description
The plugin does not check the capability of the user making a membership purchase, and does not validate the payment method or the plan submitted with it, allowing any authenticated user such as a subscriber to be granted the WordPress role attached to a paid plan without paying for it. Where the site owner has mapped a plan to a privileged role, this leads to privilege escalation up to administrator.
Proof of Concept
Affects Plugins
References
CVE
Classification
Type
PRIVESC
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Karthik Ramakrishnan
Submitter
Karthik Ramakrishnan
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-09-11 (about 2 days ago)
Added
2026-09-11 (about 1 day ago)
Last Updated
2026-09-11 (about 1 day ago)