PT-2026-83392 · WordPress · Member Hero
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
MemberHero WordPress plugin versions prior to 7.0
Description
The plugin fails to restrict account fields during the frontend registration process. This allows unauthenticated attackers to register a new user with an arbitrary role, such as Administrator, which can lead to a full site takeover and the compromise of existing accounts.
Recommendations
Deactivate and remove the plugin versions prior to 7.0 until a version that fully resolves this issue is released.
Disable public registration and restrict access to the registration functionality.
Monitor the site for unexpected administrator accounts.
Exploit
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Member Hero