PT-2026-86313 · Jfarthing84 · Theme My Login

·

CVE-2026-83628

·

Publicado

2026-09-05

·

Atualizado

2026-09-05

CVSS v3.1

4.3

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
The Theme My Login plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 7.1.15 on Multisite installations. This is due to the tml ms signup handler() function's gimmeanotherblog branch failing to enforce the network's active signup registration policy, checking only is user logged in() while sibling branches such as validate-blog-signup apply the full policy gate. This makes it possible for authenticated attackers, with Subscriber-level access and above, to directly POST stage=gimmeanotherblog to Theme My Login's signup route, bypassing the configured registration policy entirely — even when it is set to none or user — which causes wpmu create blog() to execute with the attacker's user ID, after which WordPress core assigns the Administrator role on the newly created subsite via add user to blog(). The privilege gain is scoped to the newly created subsite only; the attacker's account retains Subscriber-level access on the main site and does not obtain Super Admin or network-level capabilities such as manage network or manage sites.

Correção

Missing Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-83628

Produtos afetados

Theme My Login