PT-2026-27267 · Wpeverest · User Registration & Membership – Free & Paid Memberships

Darkestmode

·

Published

2026-03-23

·

Updated

2026-03-24

·

CVE-2026-4056

CVSS v3.1

5.4

Medium

AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
The User Registration & Membership plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the Content Access Rules REST API endpoints in versions 5.0.1 through 5.1.4. This is due to the check permissions() method only checking for edit posts capability instead of an administrator-level capability. This makes it possible for authenticated attackers, with Contributor-level access and above, to list, create, modify, toggle, duplicate, and delete site-wide content restriction rules, potentially exposing restricted content or denying legitimate user access.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-4056

Affected Products

User Registration & Membership – Free & Paid Memberships