PT-2026-36994 · WordPress · User Registration & Membership

Hunter Jensen

·

Published

2026-05-05

·

Updated

2026-05-05

·

CVE-2026-3601

CVSS v3.1

4.3

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions User Registration & Membership plugin for WordPress versions prior to 5.1.5
Description A missing capability check in the embed form action() function allows authenticated attackers with Contributor-level access or higher to perform unauthorized modification of data. This flaw enables these users to append shortcode content to arbitrary pages that they do not own or have permission to edit.
Recommendations Update the plugin to version 5.1.5 or later. As a temporary workaround, restrict access to the embed form action() function for users with Contributor-level permissions.

Fix

Missing Authorization

Weakness Enumeration

Related Identifiers

CVE-2026-3601

Affected Products

User Registration & Membership