← WordPress Vulnerabilities
WordPress security by component

MemberGlut

MemberGlut is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Jul 27, 2026; the highest CVE/CNA score is 9.8.

Plugin slug: memberglut

CVE-2026-12394: MemberGlut registration permits unauthenticated administrator creation

MemberGlut before 1.1.5 accepts a caller-controlled role in its front-end registration flow without validating that the role is safe to assign. An unauthenticated attacker can register a new account with an arbitrary role, including administrator, and obtain full control of the WordPress site. The CNA record does not disclose the registration action, role parameter or user-creation function.

PublishedJul 27, 2026
Known safe version1.1.5
Safe version
Jul 27, 2026 CVE-2026-12394
MemberGlut registration permits unauthenticated administrator creation
MemberGlut before 1.1.5 accepts a caller-controlled role in its front-end registration flow without validating that the role is safe to assign. An unauthenticated attacker can register a new account with an arbitrary role, including administrator, and obtain full control of the WordPress site. The CNA record does not disclose the registration action, role parameter or user-creation function.
1.1.5
CVE9.8
NVDPending