CyberRota Analysis
AI-GeneratedThe User Registration & Membership plugin for WordPress versions prior to 5.2.8 is vulnerable, allowing authenticated users with Author-level access or higher to assign themselves arbitrary roles, potentially escalating their privileges to Administrator. This flaw poses a significant risk as it can lead to unauthorized access and control over the WordPress site. WordPress administrators and security teams should prioritize this vulnerability to mitigate the risk of privilege escalation and protect their environments.
Original NVD Description
The User Registration & Membership WordPress plugin before 5.2.8 does not properly restrict who may author a membership plan or validate the plan a user attaches to their own account, allowing authenticated users with Author-level access and above to assign themselves an arbitrary role and escalate their privileges to Administrator.