Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
5.3

WordPress User Registration Plugin Exposes New User Accounts to Deletion

CVE-2026-2356
Summary

A security weakness in the User Registration & Membership plugin for WordPress allows someone to delete new user accounts created on your site, without needing a password. This is a concern for sites that rely on user registration and membership features. To stay safe, update the plugin to the latest version.

Original title
The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and includi...
Original description
The User Registration & Membership – Custom Registration Form, Login Form, and User Profile plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.2 via the 'register_member' function, due to missing validation on the 'member_id' user controlled key. This makes it possible for unauthenticated attackers to delete arbitrary user accounts that newly registered on the site who has the 'urm_user_just_created' user meta set.
nvd CVSS3.1 5.3
Vulnerability type
CWE-284 Improper Access Control
Published: 26 Feb 2026 · Updated: 12 Mar 2026 · First seen: 6 Mar 2026