WordPress Plugin Vulnerabilities

User Registration & Membership < 5.2.8 - Author+ Privilege Escalation to Administrator

Description

The plugin does not properly restrict who may author a membership plan or validate the plan a user attaches to their own account, allowing authenticated users with Author-level access and above to assign themselves an arbitrary role and escalate their privileges to Administrator.

Proof of Concept

Affects Plugins

Fixed in 5.2.8

References

Classification

Miscellaneous

Original Researcher
Baikuya
Submitter
Jonathan Dersch
Submitter twitter
Verified
Yes

Timeline

Publicly Published
2026-09-11 (about 2 days ago)
Added
2026-09-11 (about 1 day ago)
Last Updated
2026-09-11 (about 1 day ago)

Other