CVE-2026-79996
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-79996 is an authenticated privilege escalation vulnerability in the User Registration & Membership WordPress plugin affecting all versions before 5.2.6. The flaw allows authenticated users who have been granted plugin management capability — but not full administrator access — to change arbitrary site options and escalate their privileges to administrator. It was publicly disclosed on August 26, 2026, and carries a CVSS score of 7.2 (High) (WPScan).

Technical details

The root cause is a missing capability check (CWE-269: Improper Privilege Management) when the plugin saves its login settings, classified under OWASP Top 10 A2: Broken Authentication and Session Management. An authenticated user with the plugin's management capability can send crafted requests to the login settings save endpoint without the server verifying whether the user holds full administrator privileges, allowing arbitrary WordPress site options to be modified. This type of flaw is common in WordPress plugins that implement custom roles without properly gating sensitive administrative actions. A proof-of-concept is scheduled for public release on September 26, 2026, to allow time for users to update (WPScan).

Impact

Successful exploitation allows a lower-privileged authenticated user (one granted only plugin management capability) to escalate their privileges to full WordPress administrator, resulting in complete site compromise. An attacker with administrator access can install malicious plugins, create backdoor accounts, exfiltrate sensitive data, deface the site, or pivot to the underlying server depending on hosting configuration. The integrity and confidentiality of the entire WordPress installation are at risk (WPScan).

Exploitability

The vulnerability requires authentication, specifically a user account with the User Registration & Membership plugin management capability. No public exploit code is currently available; a PoC is scheduled for release on September 26, 2026. The EPSS score is reported as 0.0 at time of disclosure, and there is no current evidence of in-the-wild exploitation or CISA KEV catalog listing (WPScan, VulDB).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the User Registration & Membership plugin in a version prior to 5.2.6 using tools like WPScan or by inspecting plugin metadata in publicly accessible readme.txt files.
  2. Obtain low-privileged access: Acquire or create an account on the target WordPress site that has been granted the User Registration & Membership plugin management capability but lacks full administrator privileges.
  3. Craft malicious request: Send an authenticated HTTP POST request to the plugin's login settings save endpoint, including arbitrary WordPress site option values (e.g., modifying siteurl, admin_email, or user role assignments) without a valid administrator nonce or capability check being enforced.
  4. Escalate privileges: Modify site options to promote the attacker's account to administrator role, or set a known value for a critical option that grants administrative access.
  5. Achieve full site control: Log in or refresh session as a full WordPress administrator to install plugins, create backdoor accounts, or perform further malicious actions (WPScan).

Indicators of compromise

  • Logs: WordPress access logs showing authenticated POST requests to the User Registration & Membership plugin's login settings endpoint from non-administrator user accounts; unexpected changes to WordPress options logged in the database (wp_options table).
  • File System: Newly installed plugins or themes not authorized by legitimate administrators; unexpected PHP files added to the WordPress installation directory.
  • Database: Changes to the wp_options table (e.g., siteurl, admin_email, default_role) made by a non-administrator user; new entries in wp_users or wp_usermeta granting administrator capabilities to unexpected accounts.
  • Process/Behavior: Unexpected administrator-level actions (plugin installs, user role changes) attributed to accounts that should only have plugin management capability in WordPress audit logs.

Mitigation and workarounds

Update the User Registration & Membership WordPress plugin to version 5.2.6 or later, which introduces the required capability check when saving login settings. Site administrators should audit user accounts that have been granted plugin management capabilities and review the wp_options table for unauthorized changes. Until patching is possible, consider revoking plugin management capabilities from untrusted users or disabling the plugin (WPScan).

Community reactions

The vulnerability was discovered and submitted by researcher Artus KG and verified by WPScan. No significant broader media coverage or notable social media commentary has been identified at this time beyond the initial WPScan disclosure (WPScan).

Additional resources


SourceThis report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-6128NONEN/A
  • all-in-one-wp-migration-unlimited-extension
NoYesAug 28, 2026
CVE-2026-5510NONEN/A
  • give
NoYesAug 28, 2026
CVE-2026-79996NONEN/A
  • user-registration
NoYesAug 28, 2026
CVE-2026-79995NONEN/A
  • user-registration
NoYesAug 28, 2026
CVE-2026-79706NONEN/A
  • breeze
NoYesAug 28, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management