PatchSiren cyber security CVE debrief
CVE-2026-1865 User Registration & Membership CVE debrief
The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to SQL Injection via the ‘membership_ids[]’ parameter in all versions up to, and including, 5.1.2. This vulnerability allows authenticated attackers, with Subscriber-level access and above, to append additional SQL queries into existing queries, potentially leading to sensitive information disclosure. Administrators and users of WordPress sites utilizing the User Registration & Membership plugin should be aware of this vulnerability and take immediate action to protect their sites.
- Vendor
- User Registration & Membership
- Product
- User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder
- CVSS
- MEDIUM 6.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-04-08
- Original CVE updated
- 2026-07-24
- Advisory published
- 2026-04-08
- Advisory updated
- 2026-07-24
Who should care
Administrators and users of WordPress sites utilizing the User Registration & Membership plugin should be aware of this vulnerability and take immediate action to protect their sites. This includes updating the plugin, implementing strong security measures, and monitoring for suspicious activity. Vulnerability management and security teams should prioritize this issue due to its potential impact on sensitive information disclosure.
Technical summary
The User Registration & Membership plugin for WordPress is vulnerable to SQL Injection due to insufficient escaping on the user-supplied 'membership_ids[]' parameter and lack of sufficient preparation on the existing SQL query. This vulnerability, rated with a CVSS score of 6.5 (MEDIUM), can be exploited by authenticated attackers with Subscriber-level access and above. The vulnerability allows attackers to append additional SQL queries into existing queries, potentially leading to sensitive information disclosure from the database.
Defensive priority
High priority for WordPress administrators and users of the affected plugin due to potential for sensitive information disclosure.
Recommended defensive actions
- Update the User Registration & Membership plugin to the latest version.
- Implement strong passwords and authentication measures for all users.
- Monitor database activity for suspicious queries.
- Consider using a Web Application Firewall (WAF) to detect and prevent SQL injection attacks.
- Regularly review and update plugins and themes to prevent known vulnerabilities.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The CVE record was published on 2026-04-08T12:16:20.440Z and last modified on 2026-07-24T20:10:00.147Z. The NVD entry is currently Deferred. Evidence is limited to CVE and NVD information. Defenders should verify affected deployments, review official advisories, and monitor for suspicious database queries.
Official resources
AI-assisted PatchSiren debrief based on the supplied source corpus. The CVE record was published on 2026-04-08T12:16:20.440Z and has not been modified since then. The NVD entry is currently Deferred.