CVE-2026-79996
WordPress Analyse et atténuation des vulnérabilités

Aperçu

CVE-2026-79996 is an authenticated privilege escalation vulnerability in the User Registration & Membership WordPress plugin affecting all versions before 5.2.6. The flaw allows authenticated users who have been granted plugin management capability — but not full administrator access — to change arbitrary site options and escalate their privileges to administrator. It was publicly disclosed on August 26, 2026, and carries a CVSS score of 7.2 (High) (WPScan).

Détails techniques

The root cause is a missing capability check (CWE-269: Improper Privilege Management) when the plugin saves its login settings, classified under OWASP Top 10 A2: Broken Authentication and Session Management. An authenticated user with the plugin's management capability can send crafted requests to the login settings save endpoint without the server verifying whether the user holds full administrator privileges, allowing arbitrary WordPress site options to be modified. This type of flaw is common in WordPress plugins that implement custom roles without properly gating sensitive administrative actions. A proof-of-concept is scheduled for public release on September 26, 2026, to allow time for users to update (WPScan).

Impact

Successful exploitation allows a lower-privileged authenticated user (one granted only plugin management capability) to escalate their privileges to full WordPress administrator, resulting in complete site compromise. An attacker with administrator access can install malicious plugins, create backdoor accounts, exfiltrate sensitive data, deface the site, or pivot to the underlying server depending on hosting configuration. The integrity and confidentiality of the entire WordPress installation are at risk (WPScan).

Exploitabilité

The vulnerability requires authentication, specifically a user account with the User Registration & Membership plugin management capability. No public exploit code is currently available; a PoC is scheduled for release on September 26, 2026. The EPSS score is reported as 0.0 at time of disclosure, and there is no current evidence of in-the-wild exploitation or CISA KEV catalog listing (WPScan, VulDB).

Étapes d’exploitation

  1. Reconnaissance: Identify WordPress sites running the User Registration & Membership plugin in a version prior to 5.2.6 using tools like WPScan or by inspecting plugin metadata in publicly accessible readme.txt files.
  2. Obtain low-privileged access: Acquire or create an account on the target WordPress site that has been granted the User Registration & Membership plugin management capability but lacks full administrator privileges.
  3. Craft malicious request: Send an authenticated HTTP POST request to the plugin's login settings save endpoint, including arbitrary WordPress site option values (e.g., modifying siteurl, admin_email, or user role assignments) without a valid administrator nonce or capability check being enforced.
  4. Escalate privileges: Modify site options to promote the attacker's account to administrator role, or set a known value for a critical option that grants administrative access.
  5. Achieve full site control: Log in or refresh session as a full WordPress administrator to install plugins, create backdoor accounts, or perform further malicious actions (WPScan).

Indicateurs de compromis

  • Logs: WordPress access logs showing authenticated POST requests to the User Registration & Membership plugin's login settings endpoint from non-administrator user accounts; unexpected changes to WordPress options logged in the database (wp_options table).
  • File System: Newly installed plugins or themes not authorized by legitimate administrators; unexpected PHP files added to the WordPress installation directory.
  • Database: Changes to the wp_options table (e.g., siteurl, admin_email, default_role) made by a non-administrator user; new entries in wp_users or wp_usermeta granting administrator capabilities to unexpected accounts.
  • Process/Behavior: Unexpected administrator-level actions (plugin installs, user role changes) attributed to accounts that should only have plugin management capability in WordPress audit logs.

Atténuation et solutions de contournement

Update the User Registration & Membership WordPress plugin to version 5.2.6 or later, which introduces the required capability check when saving login settings. Site administrators should audit user accounts that have been granted plugin management capabilities and review the wp_options table for unauthorized changes. Until patching is possible, consider revoking plugin management capabilities from untrusted users or disabling the plugin (WPScan).

Réactions de la communauté

The vulnerability was discovered and submitted by researcher Artus KG and verified by WPScan. No significant broader media coverage or notable social media commentary has been identified at this time beyond the initial WPScan disclosure (WPScan).

Ressources additionnelles


SourceCe rapport a été généré à l’aide de l’IA

Apparenté WordPress Vulnérabilités:

Identifiant CVE

Sévérité

Score

Technologies

Nom du composant

Exploit CISA KEV

A corrigé

Date de publication

CVE-2026-6128NONEN/A
  • all-in-one-wp-migration-unlimited-extension
NonOuiAug 28, 2026
CVE-2026-5510NONEN/A
  • give
NonOuiAug 28, 2026
CVE-2026-79996NONEN/A
  • user-registration
NonOuiAug 28, 2026
CVE-2026-79995NONEN/A
  • user-registration
NonOuiAug 28, 2026
CVE-2026-79706NONEN/A
  • breeze
NonOuiAug 28, 2026

Évaluation gratuite des vulnérabilités

Évaluez votre posture de sécurité dans le cloud

Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.

Demander une évaluation

Obtenez une démo personnalisée

Prêt(e) à voir Wiz en action ?

"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
David EstlickRSSI
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
Adam FletcherChef du service de sécurité
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."
Greg PoniatowskiResponsable de la gestion des menaces et des vulnérabilités