
CVE-2026-3601 The User Registration & Membership plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `embed_form_action()… https://www.cve.org/CVERecord?id=CVE-2026-3601
Post summary
The post announces that the WordPress User Registration & Membership plugin has a missing capability check that enables unauthorized data modification (CVE‑2026‑3601).
