The User Registration & Membership WordPress plugin before 5.2.2 does not perform an authorization check on a membership-upgrade action and derives the user to modify from a caller-supplied identifier instead of the current user, allowing any authenticated user such as a subscriber to change another user's WordPress role and membership tier.
We have discovered 6,601 live websites that are affected by CVE-2026-11963.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 6,601 live websites (92% of User Registration install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 140 versions ( 98% of all versions) |
| 1,855 websites | |
| 510 websites | |
| 499 websites | |
| 329 websites | |
| 309 websites | |
| 258 websites | |
| 168 websites | |
| 157 websites | |
| 157 websites | |
| 151 websites |
| .com | 2,664 websites |
| .org | 459 websites |
| .it | 393 websites |
| .de | 193 websites |
| .co.uk | 152 websites |
| .com.br | 152 websites |
| .net | 140 websites |
| .com.au | 135 websites |
| .nl | 124 websites |
| .fr | 110 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| ****************.com | **,*** | ||
| *********.com | **,*** | ||
| ******.***.my | **,*** | ||
| ************.com | **,*** | ||
| *************.com | **,*** | ||
| ********.de | **,*** | ||
| ************.**.il | **,*** | ||
| *************.com | **,*** | ||
| ***.**.th | **,*** | ||
| ********.com | ***,*** |
FAQ