
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-79996 is an authenticated privilege escalation vulnerability in the User Registration & Membership WordPress plugin affecting all versions before 5.2.6. The flaw allows authenticated users who have been granted plugin management capability — but not full administrator access — to change arbitrary site options and escalate their privileges to administrator. It was publicly disclosed on August 26, 2026, and carries a CVSS score of 7.2 (High) (WPScan).
The root cause is a missing capability check (CWE-269: Improper Privilege Management) when the plugin saves its login settings, classified under OWASP Top 10 A2: Broken Authentication and Session Management. An authenticated user with the plugin's management capability can send crafted requests to the login settings save endpoint without the server verifying whether the user holds full administrator privileges, allowing arbitrary WordPress site options to be modified. This type of flaw is common in WordPress plugins that implement custom roles without properly gating sensitive administrative actions. A proof-of-concept is scheduled for public release on September 26, 2026, to allow time for users to update (WPScan).
Successful exploitation allows a lower-privileged authenticated user (one granted only plugin management capability) to escalate their privileges to full WordPress administrator, resulting in complete site compromise. An attacker with administrator access can install malicious plugins, create backdoor accounts, exfiltrate sensitive data, deface the site, or pivot to the underlying server depending on hosting configuration. The integrity and confidentiality of the entire WordPress installation are at risk (WPScan).
The vulnerability requires authentication, specifically a user account with the User Registration & Membership plugin management capability. No public exploit code is currently available; a PoC is scheduled for release on September 26, 2026. The EPSS score is reported as 0.0 at time of disclosure, and there is no current evidence of in-the-wild exploitation or CISA KEV catalog listing (WPScan, VulDB).
siteurl, admin_email, or user role assignments) without a valid administrator nonce or capability check being enforced.wp_options table).wp_options table (e.g., siteurl, admin_email, default_role) made by a non-administrator user; new entries in wp_users or wp_usermeta granting administrator capabilities to unexpected accounts.Update the User Registration & Membership WordPress plugin to version 5.2.6 or later, which introduces the required capability check when saving login settings. Site administrators should audit user accounts that have been granted plugin management capabilities and review the wp_options table for unauthorized changes. Until patching is possible, consider revoking plugin management capabilities from untrusted users or disabling the plugin (WPScan).
The vulnerability was discovered and submitted by researcher Artus KG and verified by WPScan. No significant broader media coverage or notable social media commentary has been identified at this time beyond the initial WPScan disclosure (WPScan).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."