CVE-2026-1779

The User Registration & Membership plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.1.2. This is due to incorrect authentication in the 'register_member' function. This makes it possible for unauthenticated attackers to log in a newly registered user on the site who has the 'urm_user_just_created' user meta set.
Configurations

No configuration.

History

27 Feb 2026, 14:06

Type Values Removed Values Added
Summary
  • (es) El plugin User Registration & Membership para WordPress es vulnerable a una omisión de autenticación en versiones hasta la 5.1.2, inclusive. Esto se debe a una autenticación incorrecta en la función 'register_member'. Esto posibilita que atacantes no autenticados inicien sesión como un usuario recién registrado en el sitio que tiene establecida la meta de usuario 'urm_user_just_created'.

26 Feb 2026, 03:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-02-26 03:16

Updated : 2026-02-27 14:06


NVD link : CVE-2026-1779

Mitre link : CVE-2026-1779

CVE.ORG link : CVE-2026-1779


JSON object : View

Products Affected

No product.

CWE
CWE-288

Authentication Bypass Using an Alternate Path or Channel