WordPress security by component
memberglut
memberglut (memberglut) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Jul 27, 2026; the highest published CVSS base score is 9.8.
Plugin slug:
memberglutLatest vulnerability
CVE-2026-12394: MemberGlut registration permits unauthenticated administrator creation
MemberGlut before 1.1.5 accepts a caller-controlled role in its front-end registration flow without validating that the role is safe to assign. An unauthenticated attacker can register a new account with an arbitrary role, including administrator, and obtain full control of the WordPress site.
| Safe version |
|
||
|---|---|---|---|
| Jul 27, 2026 |
CVE-2026-12394
MemberGlut registration permits unauthenticated administrator creation
MemberGlut before 1.1.5 accepts a caller-controlled role in its front-end registration flow without validating that the role is safe to assign. An unauthenticated attacker can register a new account with an arbitrary role, including administrator, and obtain full control of the WordPress site.
|
1.1.5 |
CVE9.8
NVDPending
|