WordPress Plugin Vulnerabilities
User Registration & Membership < 5.2.8 - Author+ Privilege Escalation to Administrator
Description
The plugin does not properly restrict who may author a membership plan or validate the plan a user attaches to their own account, allowing authenticated users with Author-level access and above to assign themselves an arbitrary role and escalate their privileges to Administrator.
Proof of Concept
Affects Plugins
References
CVE
Classification
Type
PRIVESC
OWASP top 10
CWE
CVSS
Miscellaneous
Original Researcher
Baikuya
Submitter
Jonathan Dersch
Submitter twitter
Verified
Yes
WPVDB ID
Timeline
Publicly Published
2026-09-11 (about 2 days ago)
Added
2026-09-11 (about 1 day ago)
Last Updated
2026-09-11 (about 1 day ago)