PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-16736 User Registration & Membership CVE debrief

The User Registration & Membership WordPress plugin before 5.2.6 does not enforce the site's registration-disabled setting when processing registration-form submissions, allowing unauthenticated users to create new accounts even when the administrator has turned off open registration. This issue affects WordPress sites using the User Registration & Membership plugin. The plugin's registration form submission process is vulnerable, enabling unauthorized account creation. Administrators should verify the plugin version and review site registration settings to address this issue. The evidence for this CVE is limited, and verification of the plugin version and site registration settings is necessary. Affected deployments may exist in managed environments, and owners should be assigned for follow-up.

Vendor
User Registration & Membership
Product
User Registration & Membership WordPress plugin
CVSS
Unknown
CISA KEV
Not listed in stored evidence
Original CVE published
2026-08-05
Original CVE updated
2026-08-05
Advisory published
2026-08-05
Advisory updated
2026-08-05

Who should care

Administrators of WordPress sites using the User Registration & Membership plugin should verify the plugin version and consider updating to version 5.2.6 or later to address this issue. They should also review site registration settings and assign an owner for follow-up in managed environments. Vulnerability management and security teams should track exceptions and retest remediated assets.

Technical summary

The User Registration & Membership WordPress plugin before 5.2.6 does not enforce the site's registration-disabled setting, allowing unauthenticated users to create new accounts. This issue affects administrators of WordPress sites using the User Registration & Membership plugin. The plugin's registration form submission process is vulnerable, and defenders should verify the plugin version and review site registration settings.

Defensive priority

Administrators should verify the plugin version and consider updating to version 5.2.6 or later to address this issue.

Recommended defensive actions

  • Verify the User Registration & Membership plugin version
  • Update to version 5.2.6 or later if necessary
  • Review site registration settings
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review

Evidence notes

The evidence for this CVE is limited. Verification of the User Registration & Membership plugin version and site registration settings is necessary. Affected deployments may exist in managed environments, and owners should be assigned for follow-up. The CVE record was published on 2026-08-05T07:16:36.433Z and has not been modified since then. Defenders should verify the plugin version and review site registration settings.

Official resources

AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-08-05T07:16:36.433Z and has not been modified since then.