
PEACH
Un cadre d’isolation des locataires
CVE-2026-79996 is an authenticated privilege escalation vulnerability in the User Registration & Membership WordPress plugin affecting all versions before 5.2.6. The flaw allows authenticated users who have been granted plugin management capability — but not full administrator access — to change arbitrary site options and escalate their privileges to administrator. It was publicly disclosed on August 26, 2026, and carries a CVSS score of 7.2 (High) (WPScan).
The root cause is a missing capability check (CWE-269: Improper Privilege Management) when the plugin saves its login settings, classified under OWASP Top 10 A2: Broken Authentication and Session Management. An authenticated user with the plugin's management capability can send crafted requests to the login settings save endpoint without the server verifying whether the user holds full administrator privileges, allowing arbitrary WordPress site options to be modified. This type of flaw is common in WordPress plugins that implement custom roles without properly gating sensitive administrative actions. A proof-of-concept is scheduled for public release on September 26, 2026, to allow time for users to update (WPScan).
Successful exploitation allows a lower-privileged authenticated user (one granted only plugin management capability) to escalate their privileges to full WordPress administrator, resulting in complete site compromise. An attacker with administrator access can install malicious plugins, create backdoor accounts, exfiltrate sensitive data, deface the site, or pivot to the underlying server depending on hosting configuration. The integrity and confidentiality of the entire WordPress installation are at risk (WPScan).
The vulnerability requires authentication, specifically a user account with the User Registration & Membership plugin management capability. No public exploit code is currently available; a PoC is scheduled for release on September 26, 2026. The EPSS score is reported as 0.0 at time of disclosure, and there is no current evidence of in-the-wild exploitation or CISA KEV catalog listing (WPScan, VulDB).
siteurl, admin_email, or user role assignments) without a valid administrator nonce or capability check being enforced.wp_options table).wp_options table (e.g., siteurl, admin_email, default_role) made by a non-administrator user; new entries in wp_users or wp_usermeta granting administrator capabilities to unexpected accounts.Update the User Registration & Membership WordPress plugin to version 5.2.6 or later, which introduces the required capability check when saving login settings. Site administrators should audit user accounts that have been granted plugin management capabilities and review the wp_options table for unauthorized changes. Until patching is possible, consider revoking plugin management capabilities from untrusted users or disabling the plugin (WPScan).
The vulnerability was discovered and submitted by researcher Artus KG and verified by WPScan. No significant broader media coverage or notable social media commentary has been identified at this time beyond the initial WPScan disclosure (WPScan).
Source: Ce rapport a été généré à l’aide de l’IA
Évaluation gratuite des vulnérabilités
Évaluez vos pratiques de sécurité cloud dans 9 domaines de sécurité pour évaluer votre niveau de risque et identifier les failles dans vos défenses.
Obtenez une démo personnalisée
"La meilleure expérience utilisateur que j’ai jamais vue, offre une visibilité totale sur les workloads cloud."
"Wiz fournit une interface unique pour voir ce qui se passe dans nos environnements cloud."
"Nous savons que si Wiz identifie quelque chose comme critique, c’est qu’il l’est réellement."