← WordPress Vulnerabilities
WordPress security by component

memberglut

memberglut (memberglut) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Jul 27, 2026; the highest published CVSS base score is 9.8.

Plugin slug: memberglut

CVE-2026-12394: MemberGlut registration permits unauthenticated administrator creation

MemberGlut before 1.1.5 accepts a caller-controlled role in its front-end registration flow without validating that the role is safe to assign. An unauthenticated attacker can register a new account with an arbitrary role, including administrator, and obtain full control of the WordPress site.

PublishedJul 27, 2026
Known safe version1.1.5
Published vulnerabilities for memberglut
Safe version
Jul 27, 2026 CVE-2026-12394
MemberGlut registration permits unauthenticated administrator creation
MemberGlut before 1.1.5 accepts a caller-controlled role in its front-end registration flow without validating that the role is safe to assign. An unauthenticated attacker can register a new account with an arbitrary role, including administrator, and obtain full control of the WordPress site.
1.1.5
CVE9.8
NVDPending