User Registration & Membership Plugin Vulnerability in WordPress
CVE-2026-6145
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 14 May 2026
What is CVE-2026-6145?
The User Registration & Membership plugin for WordPress is susceptible to a Missing Authorization vulnerability. This flaw arises from the is_admin_creation_process() method, which solely depends on the action=createuser parameter present in the $_REQUEST superglobal. It lacks any authentication or capability checks, allowing unauthenticated attackers to bypass the admin approval process when creating new accounts through a fallback submission path. This security oversight makes it essential for users to apply the latest updates and review their security settings to prevent unauthorized access.
Affected Version(s)
User Registration & Membership β Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder 0 <= 5.1.5