CVE-2026-12394
Description
The MemberGlut WordPress plugin before 1.1.5 does not validate the role chosen during front-end registration, allowing unauthenticated users to register an account with an arbitrary role, including administrator, leading to full site compromise.
Metadata
Severity & Metrics
No CVSS data available.
Affected products (1)
| Vendor | Product | Platform | Versions |
|---|---|---|---|
| Unknown | MemberGlut | — | 0 < 1.1.5 |
Weakness (CWE)
| CWE | Source | Description |
|---|---|---|
| — | cna | CWE-269 Improper Privilege Management |