PT-2026-22113 · WordPress · User Registration & Membership – Custom Registration Form Builder

Hoshino

·

Published

2026-02-26

·

Updated

2026-02-26

·

CVE-2026-2356

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions User Registration & Membership – Custom Registration Form, Login Form, and User Profile versions prior to 5.1.3
Description The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress contains a flaw due to missing validation on the member id user-controlled key within the register member function. This insecure direct object reference allows unauthenticated attackers to delete arbitrary user accounts that recently registered on the site and have the urm user just created user meta set.
Recommendations Update User Registration & Membership – Custom Registration Form, Login Form, and User Profile to version 5.1.3 or later.

Fix

Improper Access Control

Weakness Enumeration

Related Identifiers

CVE-2026-2356

Affected Products

User Registration & Membership – Custom Registration Form Builder