CVE Explorer
CVE-2026-12497
The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.16.18 does not consistently enforce the role restriction configured on its front-end registration role-selection field. The set of roles offered to the visitor and the set of roles the registration handler accepts are derived by two different parsers, and for some valid ways of configuring the offered roles the handler ignores the restriction and falls back to acc
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"description":"CWE-269 Improper Privilege Management","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:ac3d9236a42e097d82be5bd1ea2b83fc76d1828085e554496a68d38076cfd77e · sha256:f0c29ca32f9b2e3c… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-269","description":"CWE-269 Improper Privilege Management","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:ac3d9236a42e097d82be5bd1ea2b83fc76d1828085e554496a68d38076cfd77e · sha256:f0c29ca32f9b2e3c… · /containers/adp/0/problemTypes/0/descriptions/0
Affected products and versions
1 source assertion{"defaultStatus":"unaffected","product":"Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content","vendor":"Unknown","versions":[{"lessThan":"4.16.18","status":"affected","version":"0","versionType":"semver"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:ac3d9236a42e097d82be5bd1ea2b83fc76d1828085e554496a68d38076cfd77e · sha256:f0c29ca32f9b2e3c… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"NETWORK","availabilityImpact":"NONE","baseScore":7.5,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"NONE","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:ac3d9236a42e097d82be5bd1ea2b83fc76d1828085e554496a68d38076cfd77e · sha256:f0c29ca32f9b2e3c… · /containers/adp/0/metrics/0/cvssV3_1
CWE assertions
2 source assertions{"description":"CWE-269 Improper Privilege Management","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:ac3d9236a42e097d82be5bd1ea2b83fc76d1828085e554496a68d38076cfd77e · sha256:f0c29ca32f9b2e3c… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-269","description":"CWE-269 Improper Privilege Management","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:ac3d9236a42e097d82be5bd1ea2b83fc76d1828085e554496a68d38076cfd77e · sha256:f0c29ca32f9b2e3c… · /containers/adp/0/problemTypes/0/descriptions/0
Source references
1 source assertion{"tags":["exploit","vdb-entry","technical-description"],"url":"https://wpscan.com/vulnerability/bfb14acb-051c-4bcb-adfc-10a27a00dfe7/"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:ac3d9236a42e097d82be5bd1ea2b83fc76d1828085e554496a68d38076cfd77e · sha256:f0c29ca32f9b2e3c… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.