WordPress security by component
Add User Autocomplete
Add User Autocomplete (add-user-autocomplete) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Sep 12, 2026; the highest published CVSS base score is 8.8.
Plugin slug:
add-user-autocompleteLatest vulnerability
CVE-2026-87759: Add User Autocomplete lets subscribers grant multisite administrator rights
Add User Autocomplete before 1.2 creates a pending site-membership invitation with a caller-supplied role without a capability or nonce check. On WordPress multisite, any authenticated user such as a subscriber can invite themselves with the administrator role. The authoritative export does not identify the action or role parameter.
| Safe version |
|
||
|---|---|---|---|
| Sep 12, 2026 |
CVE-2026-87759
Add User Autocomplete lets subscribers grant multisite administrator rights
Add User Autocomplete before 1.2 creates a pending site-membership invitation with a caller-supplied role without a capability or nonce check. On WordPress multisite, any authenticated user such as a subscriber can invite themselves with the administrator role. The authoritative export does not identify the action or role parameter.
|
1.2 |
CVE8.8
NVDPending
|