User Registration & Membership
cpe:2.3:a:wpeverest:user_registration_&_membership:*:*:*:*:wordpress:*:*
- < 5.2.2
A vulnerability exists in the User Registration & Membership WordPress plugin in versions prior to 5.2.2. The issue arises because the plugin does not implement proper authorization checks on membership upgrade actions. Instead, it allows any authenticated user, such as a subscriber, to change another user's WordPress role and membership tier by supplying a specific identifier. This is possible because the plugin relies on user-supplied data to determine which user to modify, rather than using the currently logged-in user.
Exploitation of this vulnerability allows for unauthorized modification of user roles and membership tiers, potentially leading to privilege escalation if a higher-privileged role is assigned.
To reproduce this vulnerability, first activate the Membership module of the User Registration & Membership WordPress plugin and ensure that at least two Free membership tiers are created, each mapped to different roles. Set up an upgrade path from a lower tier (e.g., 'Basic' for Subscribers) to a higher one (e.g., 'Premium' for a distinct role). Publish a page with the membership listing shortcode. An authenticated user with a Subscriber role can then scrape the upgrade nonce from the membership listing page and use it to initiate a cross-user membership upgrade by sending a request that includes the victim's subscription ID and the desired membership tier.
Users are advised to update the User Registration & Membership WordPress plugin to version 5.2.2 or later.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.