CVE-2026-1869Disclosure

LOWCVSS 6.5 · MEDIUM

Exploit discussion active in current signal (2 latest mentions)

Immediate actions

  • Prioritize remediation for affected systems immediately
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to unauthorized modification of data due to missing validation checks in the confirm_payment() function in all versions up to, and including, 5.2.0. This makes it possible for unauthenticated attackers to bypass payment processing and activate paid memberships.

3.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

NONE

Threat summary

  • Public PoC and exploit tooling are both present
  • 2 mentions across 1 observed day

What's happening

  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • 2 total mentions across 1 day

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-06-26: 2PoC Mentioned / Linked · 2026-06-26: 1Exploit Tool / Code · 2026-06-26: 1Technical Details · 2026-06-26: 206-26
Signal classification2 categories
Disclosure
150.0%
PoC
150.0%
Referenced assets2 URLs
Full discourse2 posts
  • Atomic Edge@atomicedgeWAF
    PoC

    https://atomicedge.io/cve-proof/cve-2026-1869-user-registration-version-5-2-0-medium-vulnerability-proof-of-concept CVE-2026-1869 user-registration (CVSS Score 6.5) #WordPress plugin #vulnerability #cybersecurity #wordpressfirewall #wordpresssecurity #hacking #wpsecurity #atom…

    Post summary

    The post announces a proof‑of‑concept for CVE‑2026‑1869, a Medium‑scored user‑registration vulnerability in WordPress 5.2.0, with no indication of active exploitation or available patches.

    0000038
    11 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-1869 Unauthenticated Payment Bypass in User Registration & Membership WordPress Plugin 5.2.0 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-1869

    Post summary

    The post announces CVE‑2026‑1869, describing an unauthenticated payment bypass in the User Registration & Membership WordPress Plugin 5.2.0, with a link to further details but no PoC, exploit, patch, or exploitation evidence.

    00000109
    4.1K followersView on X

Explore more