CVE-2026-11961 is a privilege escalation vulnerability in the User Registration & Membership WordPress plugin affecting versions prior to 5.2.3. During public registration, the plugin fails to validate whether the submitted membership tier is one of the tiers permitted by the registration form before assigning the user role associated with that tier. As a result, an unauthenticated attacker can tamper with registration input to select any published membership tier and inherit its mapped role. If a published tier is associated with a highly privileged role, including administrator, the attacker can obtain that level of access at account creation time.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
Small standalone Python exploit repository for CVE-2026-11961 targeting the WordPress User Registration & Membership plugin. The repo contains only three files: LICENSE, README.md, and the main exploit script mass.py. The README describes a mass-exploitation workflow with single-target and batch modes, threading, proxy support, timeout control, JSONL output, logging, Telegram notifications, and a force flag to skip version validation. The Python script is an operational exploit rather than a detector. Visible code shows hardcoded affected versions (5.0.8 through 5.2.1), progress tracking, multithreading, result aggregation, logging, and a Telegram worker that posts status messages to the Telegram Bot API. The script appears designed to validate plugin version and then exploit an unauthenticated mass-assignment privilege-escalation flaw to register or create an administrator account using either supplied or randomly generated credentials. The code also includes hardcoded defaults for a Telegram bot token, Telegram chat ID, and an email address, which are notable observables. Because the provided mass.py content is truncated, not every internal request path can be enumerated from the snippet. However, the exploit’s purpose and structure are clear: bulk HTTP/HTTPS targeting of WordPress sites, optional version checking, exploitation to gain admin-level access, and operator reporting/output management. This is not part of a known exploit framework such as Metasploit or Nuclei; it is a standalone Python mass-exploitation tool.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
7 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.