{"id":"CVE-2026-16736","published":"2026-08-05T07:16:36.433","lastModified":"2026-08-05T16:16:52.977","description":"The User Registration & Membership  WordPress plugin before 5.2.6 does not enforce the site's registration-disabled setting when processing registration-form submissions, allowing unauthenticated users to create new accounts even when the administrator has turned off open registration.","cvssScore":7.5,"cvssSeverity":"HIGH","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","cwes":["CWE-284"],"vendors":[],"products":[],"references":[{"url":"https://wpscan.com/vulnerability/dc0d63d6-bcd9-4f14-865a-49d254a831a2/","tags":[]}],"exploitRefs":[],"hasPoc":false,"ai":{"summary":"The flaw allows unauthenticated users to bypass registration restrictions set by administrators, enabling account creation even when open registration is disabled.","exploitability":"Exploitation requires access to the WordPress plugin and knowledge of the site's registration settings; relatively easy if an attacker can identify the vulnerable version.","blast_radius":"If exploited, it could lead to unauthorized user accounts being created, potentially compromising user data or site integrity.","remediation":"Update the User Registration & Membership WordPress plugin to version 5.2.6 or later.","tags":["auth-bypass","web","wordpress"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-08-11T06:57:46.356Z"}}