PT-2026-84637 · WordPress · My Login
CVSS v3.1
5.4
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
My Login WordPress plugin versions prior to 7.2.0
Description
On multisite installations, the plugin fails to enforce the network registration settings during site signup processing. This allows unauthenticated users on certain networks and users with subscriber accounts to create new sites and automatically obtain administrator privileges over them.
Recommendations
Update the My Login WordPress plugin to version 7.2.0 or later.
Exploit
Fix
LPE
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
My Login