CVE-2026-12394: MemberGlut Plugin Lets Anyone Register as WordPress Admin
ID: b98e5390-cca6-5643-9342-54adb7df96c8
STIX ID: report--b98e5390-cca6-5643-9342-54adb7df96c8
Feed Name: CosmicBytez Labs
A critical unauthenticated privilege-escalation vulnerability (CVE-2026-12394, CVSS 9.8) in the MemberGlut WordPress plugin (<1.1.5) allows attackers to specify the role parameter during front-end registration to create administrator accounts and achieve full site compromise; administrators should update to version 1.1.5 immediately, audit and remove unauthorized admin accounts, review logs for exploitation, or temporarily disable the plugin/registration if patching is not feasible.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
