WordPress User Registration & Membership是WordPress基金会的一个用户注册与会员管理软件。 WordPress User Registration & Membership 5.2.3之前版本存在权限许可和访问控制问题漏洞,该漏洞源于未验证注册过程中提交的会员等级是否为表单允许的级别,可能导致未经验证的用户任意注册并获取管理员角色。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Unknown | User Registration & Membership | < 5.2.3 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | User Registration & Membership | 0 ~ 5.2.3 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-9810 | AI Chatbot & Workflow Automation by AIWU < 1.5.4 - Unauthenticated Privilege Escalation vi | |
| CVE-2026-13402 | Royal Elementor Addons < 1.7.1063 - Unauthenticated Private Mega Menu Template Disclosure | |
| CVE-2026-11966 | User Registration & Membership < 5.2.3 - Unauthenticated Limited User Deletion via Stripe | |
| CVE-2026-11575 | PhonePe Payment Solutions < 3.1.0 - Unauthenticated Payment Bypass via Forged Callback | |
| CVE-2026-10525 | NEX-Forms < 9.2.3 - Unauthenticated Stored XSS via Form Submission | |
| CVE-2026-12393 | WPS Bookings for WooCommerce < 3.11.7 - Subscriber+ Arbitrary Booking Order Cancellation v |
No comments yet