PT-2026-83392 · WordPress · Member Hero

·

CVE-2026-10522

·

Published

2026-08-29

·

Updated

2026-09-10

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MemberHero WordPress plugin versions prior to 7.0
Description The plugin fails to restrict account fields during the frontend registration process. This allows unauthenticated attackers to register a new user with an arbitrary role, such as Administrator, which can lead to a full site takeover and the compromise of existing accounts.
Recommendations Deactivate and remove the plugin versions prior to 7.0 until a version that fully resolves this issue is released. Disable public registration and restrict access to the registration functionality. Monitor the site for unexpected administrator accounts.

Exploit

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-10522

Affected Products

Member Hero