The User Registration & Membership WordPress plugin before 5.2.3 does not perform a capability check for unauthenticated callers on one of its membership payment actions and acts on a caller-supplied user identifier, allowing unauthenticated attackers to delete recently-registered, payment-pending user accounts.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-07-17 07:16
Updated : 2026-07-17 15:44
NVD link : CVE-2026-11966
Mitre link : CVE-2026-11966
CVE.ORG link : CVE-2026-11966
JSON object : View
Products Affected
No product.
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
