SEPTEMBER 13, 2026
Live Feed
Back to database
Case File

CVE-2026-80071

HIGH · CVSS 7.2

Source: NVD + CISA KEV + EPSS · Published 2026-09-13 · Last synced 2026-09-13

CyberRota Analysis

AI-Generated

The User Registration & Membership plugin for WordPress versions prior to 5.2.8 is vulnerable, allowing authenticated users with Author-level access or higher to assign themselves arbitrary roles, potentially escalating their privileges to Administrator. This flaw poses a significant risk as it can lead to unauthorized access and control over the WordPress site. WordPress administrators and security teams should prioritize this vulnerability to mitigate the risk of privilege escalation and protect their environments.

CVE
CVE-2026-80071
Severity
HIGH
CVSS
7.2
EPSS
N/A
WordPress

Original NVD Description

The User Registration & Membership WordPress plugin before 5.2.8 does not properly restrict who may author a membership plan or validate the plan a user attaches to their own account, allowing authenticated users with Author-level access and above to assign themselves an arbitrary role and escalate their privileges to Administrator.