{"id":"CVE-2026-86406","title":"The User Registration & Membership  WordPress plugin before 5.2.8 does not check the capability of the user making a membership purchase, and does not validate the payment method or the plan submitted with it, allowing any authenticated …","summary":"The User Registration & Membership  WordPress plugin before 5.2.8 does not check the capability of the user making a membership purchase, and does not validate the payment method or the plan submitted with it, allowing any authenticated …","severity":"high","cvss":7.5,"cvssVector":"CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H","cwe":["CWE-269"],"product":"User Registration & Membership","affected":["user_registration_membership >= 4.4.6 < 5.2.8"],"published":"2026-09-13","updated":"2026-09-14","sourceUpdated":"2026-09-14T21:10:17.423","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-86406","references":[{"url":"https://wpscan.com/vulnerability/0fb4ec40-3f92-4c7e-8877-8898b355d78d/","label":"contact@wpscan.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-13T10:42:44.062470Z"},"ingestedAt":"2026-09-14T15:23:07.471Z","epss":0.0019,"epssPercentile":0.0897,"slug":"CVE-2026-86406","body":"## Overview\n\nThe User Registration & Membership  WordPress plugin before 5.2.8 does not check the capability of the user making a membership purchase, and does not validate the payment method or the plan submitted with it, allowing any authenticated user such as a subscriber to be granted the WordPress role attached to a paid plan without paying for it. Where the site owner has mapped a plan to a privileged role, this leads to privilege escalation up to administrator.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":41,"depthScoreParts":{"impact":41.3,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}