top of page
perceptive_background_267k.jpg

The MemberGlut WordPress plugin before 1.1.5 does not validate the role chosen during front-end registration, allowing unauthenticated users to register an acc…

Published:

27 juli 2026 om 00:00:00

Alert date:

27 juli 2026 om 23:04:07

Source:

nvd.nist.gov

Click to open the original link from this advisory

Web Technologies, Identity & Access

The MemberGlut WordPress plugin versions before 1.1.5 contains a critical vulnerability where it fails to validate user roles during front-end registration. This flaw allows unauthenticated users to register accounts with arbitrary roles, including administrator-level access. Exploitation of this vulnerability can lead to full site compromise. No authentication is required to exploit this issue, making it particularly dangerous. The vulnerability is tracked as CVE-2026-12394 and has been reported via both NVD and WPScan. Site owners using the affected plugin are strongly advised to update to version 1.1.5 or later immediately. The lack of server-side role validation represents a fundamental access control failure in the plugin's registration workflow.

Technical details

Mitigation steps:

Affected products:

MemberGlut WordPress Plugin

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page