CVE-2026-16736: CWE-284 Improper Access Control in User Registration & Membership
A vulnerability in the User Registration & Membership WordPress plugin before version 5.2.6 allows unauthenticated users to create new accounts even when the site administrator has disabled open registration. This occurs because the plugin does not enforce the registration-disabled setting during registration-form submissions.
AI Analysis
Technical Summary
CVE-2026-16736 is an improper access control vulnerability (CWE-284) in the User Registration & Membership WordPress plugin versions prior to 5.2.6. The flaw allows unauthenticated attackers to bypass the site's registration-disabled setting and create new user accounts despite the administrator's intent to disable open registration. This vulnerability arises from the plugin's failure to properly enforce access control checks on registration form submissions.
Potential Impact
The vulnerability allows unauthenticated attackers to create new user accounts on affected WordPress sites even when registration is disabled by the administrator. This can lead to unauthorized account creation, potentially enabling further abuse depending on the privileges granted to new users. The CVSS score of 7.5 (high) reflects the network attack vector, no required privileges or user interaction, and high confidentiality impact due to unauthorized account creation.
Mitigation Recommendations
No official patch or remediation level is currently confirmed. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, administrators should monitor plugin updates closely and consider disabling or replacing the plugin if open registration must be strictly controlled.
CVE-2026-16736: CWE-284 Improper Access Control in User Registration & Membership
Description
A vulnerability in the User Registration & Membership WordPress plugin before version 5.2.6 allows unauthenticated users to create new accounts even when the site administrator has disabled open registration. This occurs because the plugin does not enforce the registration-disabled setting during registration-form submissions.
CVSS v3.1
Score 7.5high
Affected software
User Registration & Membership
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-16736 is an improper access control vulnerability (CWE-284) in the User Registration & Membership WordPress plugin versions prior to 5.2.6. The flaw allows unauthenticated attackers to bypass the site's registration-disabled setting and create new user accounts despite the administrator's intent to disable open registration. This vulnerability arises from the plugin's failure to properly enforce access control checks on registration form submissions.
Potential Impact
The vulnerability allows unauthenticated attackers to create new user accounts on affected WordPress sites even when registration is disabled by the administrator. This can lead to unauthorized account creation, potentially enabling further abuse depending on the privileges granted to new users. The CVSS score of 7.5 (high) reflects the network attack vector, no required privileges or user interaction, and high confidentiality impact due to unauthorized account creation.
Mitigation Recommendations
No official patch or remediation level is currently confirmed. Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, administrators should monitor plugin updates closely and consider disabling or replacing the plugin if open registration must be strictly controlled.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- WPScan
- Date Reserved
- 2026-07-23T07:49:11.677Z
- State
- PUBLISHED
Threat ID: 6a72d7aebf8831d5395e82bf
Added to database: 08/05/2026, 06:26:54 UTC
Last enriched: 08/12/2026, 15:33:30 UTC
Last updated: 09/17/2026, 22:01:33 UTC
Views: 25
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.