HomeCVE Intelligence › CVE-2026-11961
CVSS 9.1 CRITICAL Vulnerability

CVE-2026-11961: CVE-2026-11961 - User Registration & Membership < 5.2.3 - Unauthenticated Privilege Escal…

CVE ID : CVE-2026-11961 Published : July 17, 2026, 6 a.m. | 59minutes ago Description : The User Registration & Membership WordPress plugin before 5.2.3 does not validate that the membership tier submitted during public…

9.1CVSS Score
CRITICALSeverity
NOCISA KEV
VulnerabilityImpact Type

📋 Vulnerability Details

CVE IDCVE-2026-11961
VendorUnknown Vendor
Affected ProductUnknown Product
Vulnerability TypeVulnerability
CVSS Score9.1 (CRITICAL)
Actively Exploited❌ No known exploitation
Patch StatusPending Vendor Disclosure
Reported ByCYBERDUDEBIVASH SENTINEL APEX Intelligence (via sentinel_apex)

🔬 Technical Analysis

CVE ID : CVE-2026-11961

Published : July 17, 2026, 6 a.m. | 59minutes ago

Description : The User Registration & Membership WordPress plugin before 5.2.3 does not validate that the membership tier submitted during public registration is one of the tiers allowed by the registration form before assigning that tier's associated user role, allowing unauthenticated users to register into an arbitrary published membership tier and obtain its role up to administrator when such a tier

🎯 Known Indicators of Compromise

{"type":"indicator","value":"CVE-2026-11961","confidence_score":23.5,"first_seen":"2026-07-17","source_count":1}
⚡ DETECTION RULES AVAILABLE

Get CVE-2026-11961 Detection Pack

Sigma rules, YARA signatures, IOC table, and SIEM queries for Splunk, Elastic, Sentinel, and Chronicle — deployable in 5 minutes.

✓ Sigma Rules ✓ YARA Pack ✓ IOC Table ✓ SIEM Queries
🛡️ Get Detection Pack → 🔌 Access via API →

🔗 Related Intelligence