Subscriber Privilege Escalation in WCFM Membership Plugin by WordPress
CVE-2026-84756

7.1HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
3 September 2026

What is CVE-2026-84756?

The WCFM Membership Plugin for WordPress is susceptible to a privilege escalation flaw that allows subscribers to gain elevated access rights. This vulnerability affects versions up to 2.11.11 and can potentially enable unauthorized users to perform actions that should be restricted to higher-level roles. Website administrators should address this issue promptly to ensure the security of their platforms.

Affected Version(s)

WCFM Membership <= 2.11.11

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

yagamimoon | Patchstack Bug Bounty Program
.