← WordPress Vulnerabilities
WordPress security by component

Theme My Login

Theme My Login replaces standard WordPress login, registration, and password pages with customizable front-end forms.

Theme My Login (theme-my-login) is a WordPress plugin with 6 published CVE records in this archive. The latest tracked vulnerability was published Sep 05, 2026; the highest published CVSS base score is 6.5.

Plugin slug: theme-my-login

CVE-2026-83628: Theme My Login bypasses Multisite subsite-registration policy

Theme My Login through 7.1.15 does not enforce the Multisite network's active_signup policy in tml_ms_signup_handler() when a Subscriber posts stage=gimmeanotherblog to its signup route. The handler calls wpmu_create_blog() with the attacker's user ID, after which WordPress assigns that account Administrator on the new subsite. The attacker remains a Subscriber on the main site and does not gain Super Admin or network-management capabilities.

PublishedSep 05, 2026
Known safe version7.2.0
Published vulnerabilities for theme-my-login
Safe version
Sep 05, 2026 CVE-2026-83628
Theme My Login bypasses Multisite subsite-registration policy
Theme My Login through 7.1.15 does not enforce the Multisite network's active_signup policy in tml_ms_signup_handler() when a Subscriber posts stage=gimmeanotherblog to its signup route. The handler calls wpmu_create_blog() with the attacker's user ID, after which WordPress assigns that account Administrator on the new subsite. The attacker remains a Subscriber on the main site and does not gain Super Admin or network-management capabilities.
7.2.0
CVE4.3
NVDPending
Sep 02, 2026 CVE-2026-81583
Theme My Login permits unauthorized Multisite creation
Theme My Login 7.0 through 7.1.x does not enforce the network registration setting when processing Multisite signups. A Subscriber—and on some networks an unauthenticated visitor—can create a new site and receive Administrator privileges over it.
7.2.0
CVE5.4
NVDPending
Aug 06, 2026 CVE-2026-66681
Theme My Login permits cross-site request forgery
Theme My Login 7.1.14 and earlier accepts a state-changing request without adequate cross-site request-forgery protection. An unauthenticated attacker can cause a logged-in victim's browser to submit the request with the victim's session authority.
> 7.1.14
CVE4.3
NVDPending
Sep 26, 2025 CVE-2025-60098
Theme My Login: A security weakness
Theme My Login is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE6.5
NVDPending
Aug 16, 2024 CVE-2024-7422
Theme My Login: Cross-site request forgery
Theme My Login is affected by cross-site request forgery. The vulnerable path is reachable without authentication. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVDPending
Apr 17, 2024 CVE-2024-32525
Theme My Login: A security weakness
Theme My Login is affected by a security weakness. Exposure depends on how the affected operation is made reachable by the site. The resulting impact depends on how the affected component exposes the vulnerable operation.
See mitigation notes
CVE4.3
NVDPending