Unauthenticated Broken Authentication in User Registration & Membership Pro
CVE-2026-74001
9.8CRITICAL
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 20 August 2026
What is CVE-2026-74001?
This vulnerability involves unauthenticated broken authentication in the User Registration & Membership Pro plugin, exposing the affected versions to potential account takeover. Attackers can exploit this flaw to gain unauthorized access to user accounts, compromising sensitive information and user privacy. It is crucial for users of versions up to 5.4.5 to take immediate action to secure their installations and prevent unauthorized access.
Affected Version(s)
User Registration & Membership Pro <= 5.4.5