CyberRota Analysis
AI-GeneratedThe User Registration & Membership plugin for WordPress versions prior to 5.2.6 is vulnerable due to a lack of capability checks when saving login settings, enabling authenticated users with specific management capabilities to modify site options and escalate their privileges to administrator. This vulnerability poses a significant risk to site integrity and security, particularly for installations where user roles are not strictly managed. WordPress administrators and security teams should prioritize updating to the latest version to mitigate potential exploitation.
Original NVD Description
The User Registration & Membership WordPress plugin before 5.2.6 does not perform a capability check when saving its login settings, allowing authenticated users who have been granted a User Registration & Membership WordPress plugin before 5.2.6 management capability but not full administrator access to change arbitrary site options and escalate their privileges to administrator.