CVE-2026-2356: medium-severity vulnerability in wpeverest User Registration & Membership…
User Registration & Membership <= 5.1.2 - Insecure Direct Object Reference to Unauthenticated Limited User Deletion
Published · Updated
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 5.3epss 0.2%
exploitation probability
0.2%top 92% of all CVEs
observed exploitation
nono source reports it
The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.2 via the 'register_member' function, due to missing validation on the 'member_id' user controlled key. This makes it possible for unauthenticated attackers to delete arbitrary user accounts that newly registered on the site who has the 'urm_user_just_created' user meta set.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
Related CVEs — wpeverest User Registration & Membership…
In the same product, most dangerous first.
CVE-2026-1492CRITICALUser Registration & Membership <= 5.1.2 - Unauthenticated Privilege Escalation via Membership RegistrationEPSS 28.0%CVE-2023-3342CRITICALUser Registration <= 3.0.2 - Authenticated (Subscriber+) Arbitrary File UploadEPSS 1.7%CVE-2023-3343HIGHUser Registration <= 3.0.1 - Authenticated (Subscriber+) PHP Object InjectionEPSS 1.1%CVE-2024-2417HIGHUser Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin <= 3.1.5 - Missing Authorization to Authenticated (Subscriber+) Privilege EscalationEPSS 0.9%CVE-2024-3295MEDIUMUser Registration – Custom Registration Form, Login Form, and User Profile WordPress Plugin <= 3.1.5 - Missing Authorization to Unauthenticated Media DeletionEPSS 0.9%CVE-2026-6203MEDIUMUser Registration & Membership <= 5.1.4 - Unauthenticated Open Redirect via 'redirect_to_on_logout' ParameterEPSS 0.6%