PT-2026-31292 · WordPress · User Registration & Membership+1

Athiwat Tiprasaharn

+1

·

Published

2026-04-08

·

Updated

2026-04-12

·

CVE-2026-1865

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress versions up to and including 5.1.2
Description The User Registration & Membership plugin for WordPress is susceptible to SQL Injection via the membership ids[] parameter. Insufficient input sanitization and inadequate SQL query preparation allow authenticated attackers with Subscriber-level access or higher to inject additional SQL queries, potentially leading to the extraction of sensitive database information.
Recommendations Update the User Registration & Membership plugin to a version newer than 5.1.2.

Fix

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2026-1865

Affected Products

User Registration & Membership
Wordpress