{"id":"CVE-2026-79996","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-79996","summary":"The User Registration & Membership  WordPress plugin before 5.2.6 does not perform a capability check when saving its login settings, allowing authenticated users who have been granted…","details":"The User Registration & Membership  WordPress plugin before 5.2.6 does not perform a capability check when saving its login settings, allowing authenticated users who have been granted a User Registration & Membership  WordPress plugin before 5.2.6 management capability but not full administrator access to change arbitrary site options and escalate their privileges to administrator.","published":"2026-08-28T08:16:42.427","modified":"2026-08-28T08:16:42.427","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://wpscan.com/vulnerability/609bbb7c-c19a-4c72-8cef-95598a2cfc0d/"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-08-28T08:16:42.427"}}