Back to CVE List

CVE-2026-11965

MEDIUM SEVERITY

CVSS Score & Metrics

Base Score
6.5 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:N

Vulnerability Description

The User Registration & Membership WordPress plugin before 5.2.0 does not enforce payment completion before activating a paid membership subscription, allowing unauthenticated users (after self-registering an account through the open registration flow) to obtain an active subscription on any paid plan without paying and access the gated content.

Vulnerability Details

Published Date
Last Modified
Source
NVD
Vendor
Unknown
Product
User Registration & Membership

External References

Discussion (0)

Add Comment

No comments yet. Be the first!