
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-69292 is a privilege escalation vulnerability (CWE-266: Incorrect Privilege Assignment) in the e-plugins WP Membership WordPress plugin. It affects all versions through 1.6.4 and allows authenticated users with low-level privileges (e.g., Subscriber role) to escalate their access to higher privilege levels, potentially gaining administrative control. The vulnerability was reported by researcher Phat RiO on November 13, 2025, and publicly disclosed by Patchstack on January 22, 2026. It carries a CVSS v3.1 base score of 8.8 (High) (Patchstack, NVD).
The vulnerability is classified as CWE-266 (Incorrect Privilege Assignment), meaning the plugin incorrectly assigns or fails to properly validate privilege levels during certain operations, allowing a lower-privileged authenticated user to assume higher-level roles. The attack vector is network-based, requires low privileges (Subscriber-level access), no user interaction, and has low attack complexity. The specific code path or endpoint responsible for the improper privilege assignment has not been publicly detailed beyond the Patchstack advisory. No public proof-of-concept code has been released (Patchstack).
Successful exploitation allows an authenticated attacker with minimal privileges (e.g., a Subscriber account) to escalate to administrator-level access on the affected WordPress site. This could enable the attacker to modify site configurations, install malicious plugins or themes, create additional administrator accounts, access or exfiltrate sensitive user data, and fully compromise the confidentiality, integrity, and availability of the WordPress installation (Patchstack).
As of the disclosure date, there is no public proof-of-concept exploit and no confirmed evidence of active in-the-wild exploitation. The EPSS score is approximately 0.017% (0.000170), indicating a low current probability of exploitation. The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog. However, Patchstack classifies it as high priority, noting that vulnerabilities of this type are commonly used in mass-exploit campaigns targeting WordPress sites at scale (Patchstack).
/wp-content/plugins/wp-membership/)./wp-admin/) or performing actions restricted to higher roles (e.g., Administrator).wp_usermeta database table (e.g., wp_capabilities field updated to administrator).wp-content/; presence of unknown PHP files or web shells in the WordPress installation directory.As of the disclosure date (January 22, 2026), no official patch from e-plugins is available for WP Membership. Patchstack has issued a virtual patching/mitigation rule for its subscribers to block exploitation attempts until an official fix is released. Site administrators should immediately audit user roles and permissions, remove or disable the WP Membership plugin if it is not critical, restrict new user registrations, and monitor WordPress logs for suspicious privilege changes. Applying a Web Application Firewall (WAF) with WordPress-specific rules is also recommended as an interim measure (Patchstack).
Wordfence included CVE-2025-69292 in its weekly WordPress vulnerability report for the period of January 19–25, 2026, highlighting it among notable disclosures for that week (Wordfence). Patchstack, which discovered and disclosed the vulnerability through researcher Phat RiO, classified it as high priority and noted the potential for mass-exploit campaigns targeting WordPress sites. No significant broader media coverage or vendor statements from e-plugins have been identified.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."