← WordPress Vulnerabilities
WordPress security by component

MemberPress Corporate Accounts

MemberPress Corporate Accounts (memberpress-corporate-accounts) is a WordPress plugin with 1 published CVE record in this archive. The latest tracked vulnerability was published Sep 12, 2026; the highest published CVSS base score is 8.8.

Plugin slug: memberpress-corporate-accounts

CVE-2026-15451: MemberPress Corporate Accounts mass assignment creates administrators

MemberPress Corporate Accounts through 1.5.39 passes the raw userdata array from add_sub_account_user to wp_insert_user without filtering role or ID. A subscriber who holds a corporate account can create a new administrator or target an existing administrator ID and overwrite its email address. Version 1.5.39 only partially patched the issue.

PublishedSep 12, 2026
Safe version guidanceSee mitigation notes
Published vulnerabilities for memberpress-corporate-accounts
Safe version
Sep 12, 2026 CVE-2026-15451
MemberPress Corporate Accounts mass assignment creates administrators
MemberPress Corporate Accounts through 1.5.39 passes the raw userdata array from add_sub_account_user to wp_insert_user without filtering role or ID. A subscriber who holds a corporate account can create a new administrator or target an existing administrator ID and overwrite its email address. Version 1.5.39 only partially patched the issue.
See mitigation notes
CVE8.8
NVDPending