What is CVE-2026-12497?
This vulnerability was found in the Paid Membership Plugin for WordPress. In versions before 4.16.18, the role restriction configured on the front-end registration role-selection field is not consistently enforced. This could allow users to gain unauthorized roles.
Azərbaycanca: Bu zəiflik WordPress üçün Paid Membership Plugin-də aşkarlanıb. 4.16.18-dən əvvəlki versiyalarda, ön tərəfdəki qeydiyyat formasında rol seçiminə qoyulan məhdudiyyət ardıcıl tətbiq edilmir. Bu, istifadəçilərə icazəsiz rollar əldə etməyə imkan verə bilər.
Related CVEs
link basis: same weakness class CWE-863
FAQ2
Which plugin and versions are affected by CVE-2026-12497?
The vulnerability was found in the Paid Membership Plugin for WordPress and affects versions prior to 4.16.18.
What is the impact of CVE-2026-12497?
The restriction on the front-end registration role-selection field is not consistently enforced, which could allow users to gain unauthorized roles.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.