Vulnerability Description
The User Registration & Membership WordPress plugin before 5.2.6 does not perform a capability check when saving its login settings, allowing authenticated users who have been granted a User Registration & Membership WordPress plugin before 5.2.6 management capability but not full administrator access to change arbitrary site options and escalate their privileges to administrator.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
FAQ
What is CVE-2026-79996?
CVE-2026-79996 is a vulnerability with a CVSS score of 7.2 (HIGH). The User Registration & Membership WordPress plugin before 5.2.6 does not perform a capability check when saving its login settings, allowing authenticated users who have been granted a User Registra...
How severe is CVE-2026-79996?
CVE-2026-79996 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-79996?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.