CVE-2026-1321Disclosure

LOWCVSS 8.1 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.2.20. This is due to the `rcp_setup_registration_init()` function accepting any membership level ID via the `rcp_level` POST parameter without validating that the level is active or that payment is required. Combined with the `add_user_role()` method which assigns the WordPress role configured on the membership level without status checks, this makes it possible for unauthenticated attackers to register with any membership level, including inactive levels that grant privileged WordPress roles such as Administrator, or paid levels that charge a sign-up fee. The vulnerability was partially patched in version 3.2.18.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-03-05: 2Technical Details · 2026-03-05: 103-05
Signal classification1 categories
Disclosure
2100.0%
Referenced assets3 URLs
Full discourse2 posts
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-1321 - High The Membership Plugin – Restrict Content plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.2.20. This is due to the `rcp_setup_registration_i... https://www.thehackerwire.com/vulnerability/CVE-2026-1321/ https://t.co/n6x0IrJnt2

    Post summary

    CVE-2026-1321 is disclosed as a privilege escalation flaw in the Restrict Content WordPress plugin; no PoC, exploit code, patch, or active exploitation details are supplied.

    1000054
    124 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-1321 Unauthenticated Privilege Escalation in WordPress Restrict Content... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-1321 Vulnerability Alert Subscriptions: https://alerts.vulmon.com/?utm_source=twitter&utm_medium=social&utm_campaign=2102281&utm_content=1

    Post summary

    The content announces the discovery of a new WordPress privilege escalation vulnerability (CVE-2026-1321) without providing additional technical details or exploit information.

    0000041
    4.0K followersView on X

Explore more