WordPress Plugin Vulnerabilities

User Registration & Membership < 5.2.2 - Subscriber+ Cross-User Role and Membership Tier Modification via IDOR

Description

The plugin does not perform an authorization check on a membership-upgrade action and derives the user to modify from a caller-supplied identifier instead of the current user, allowing any authenticated user such as a subscriber to change another user's WordPress role and membership tier.

Proof of Concept

Affects Plugins

Fixed in 5.2.2

References

Classification

Type
IDOR
CWE

Miscellaneous

Original Researcher
Revanth Hari Narayana Matte
Submitter
Revanth Hari Narayana Matte
Verified
Yes

Timeline

Publicly Published
2026-06-22 (about 2 months ago)
Added
2026-06-22 (about 2 months ago)
Last Updated
2026-06-22 (about 2 months ago)

Other