


Perceptive Security
SOC/SIEM Consultancy

The MemberGlut WordPress plugin before 1.1.5 does not validate the role chosen during front-end registration, allowing unauthenticated users to register an acc…
Published:
26 July 2026 at 22:00:00
Alert date:
27 July 2026 at 21:04:07
Source:
nvd.nist.gov
Web Technologies, Identity & Access
The MemberGlut WordPress plugin versions before 1.1.5 contains a critical vulnerability where it fails to validate user roles during front-end registration. This flaw allows unauthenticated users to register accounts with arbitrary roles, including administrator-level access. Exploitation of this vulnerability can lead to full site compromise. No authentication is required to exploit this issue, making it particularly dangerous. The vulnerability is tracked as CVE-2026-12394 and has been reported via both NVD and WPScan. Site owners using the affected plugin are strongly advised to update to version 1.1.5 or later immediately. The lack of server-side role validation represents a fundamental access control failure in the plugin's registration workflow.
Technical details
Mitigation steps:
Affected products:
MemberGlut WordPress Plugin
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-12394
https://wpscan.com/vulnerability/6b126a3e-30d5-4bed-ba47-33e589ec2852/
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
