The User Registration & Membership WordPress plugin before 5.2.6 does not enforce the site's registration-disabled setting when processing registration-form submissions, allowing unauthenticated users to create new accounts even when the administrator has turned off open registration.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
The User Registration & Membership WordPress plugin before version 5.2.6 contains an improper access control vulnerability (CWE-284) that fails to validate the site administrator's registration settings. When administrators disable open registration to restrict account creation, this plugin ignores that configuration and processes registration form submissions anyway, allowing unauthenticated attackers to create new user accounts at will. This vulnerability affects WordPress sites relying on this plugin for membership management, particularly those in regulated industries or with strict access control requirements. The impact is significant because newly created accounts can serve as persistence mechanisms or entry points for further attacks, especially if the plugin assigns default roles with elevated permissions.
While this specific CVE does not map to active MITRE ATT&CK techniques in standard frameworks, Casky's extended reasoning capabilities would identify the underlying attack patterns associated with account creation abuse and access control bypass. Practitioners using Casky would observe findings related to account manipulation tactics—detecting anomalous user registration events that occur when registration should be administratively disabled, unusual account creation patterns from unauthenticated sources, and privilege escalation opportunities through newly provisioned accounts. The 754 security skills mapped across Casky's knowledge base would help practitioners correlate this configuration bypass with post-exploitation behaviors, enabling detection of the initial access and persistence phases that often follow successful account creation attacks. Security teams would benefit from monitoring plugin update compliance and validating that administrative settings are actually enforced at the application logic layer.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-16736. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation