← WordPress Vulnerabilities
WordPress security by component

Add User Autocomplete

Add User Autocomplete (add-user-autocomplete) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Sep 12, 2026; the highest published CVSS base score is 8.8.

Plugin slug: add-user-autocomplete

CVE-2026-87759: Add User Autocomplete lets subscribers grant multisite administrator rights

Add User Autocomplete before 1.2 creates a pending site-membership invitation with a caller-supplied role without a capability or nonce check. On WordPress multisite, any authenticated user such as a subscriber can invite themselves with the administrator role. The authoritative export does not identify the action or role parameter.

PublishedSep 12, 2026
Known safe version1.2
Published vulnerabilities for add-user-autocomplete
Safe version
Sep 12, 2026 CVE-2026-87759
Add User Autocomplete lets subscribers grant multisite administrator rights
Add User Autocomplete before 1.2 creates a pending site-membership invitation with a caller-supplied role without a capability or nonce check. On WordPress multisite, any authenticated user such as a subscriber can invite themselves with the administrator role. The authoritative export does not identify the action or role parameter.
1.2
CVE8.8
NVDPending