WordPress security by component
MemberGlut
Plugin description
MemberGlut is a WordPress component with 1 published CVE record in this archive. The latest tracked vulnerability was published Jul 27, 2026; the highest CVE/CNA score is 9.8.
Plugin slug:
memberglutLatest vulnerability
CVE-2026-12394: MemberGlut registration permits unauthenticated administrator creation
MemberGlut before 1.1.5 accepts a caller-controlled role in its front-end registration flow without validating that the role is safe to assign. An unauthenticated attacker can register a new account with an arbitrary role, including administrator, and obtain full control of the WordPress site. The CNA record does not disclose the registration action, role parameter or user-creation function.
| Safe version |
|
||
|---|---|---|---|
| Jul 27, 2026 |
CVE-2026-12394
MemberGlut registration permits unauthenticated administrator creation
MemberGlut before 1.1.5 accepts a caller-controlled role in its front-end registration flow without validating that the role is safe to assign. An unauthenticated attacker can register a new account with an arbitrary role, including administrator, and obtain full control of the WordPress site. The CNA record does not disclose the registration action, role parameter or user-creation function.
|
1.1.5 |
CVE9.8
NVDPending
|