SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-12394

CRITICAL · CVSS 9.8 EPSS 1.49%

Source: NVD + CISA KEV + EPSS · Published 2026-07-27 · Last synced 2026-08-26

CyberRota Analysis

AI-Generated

The MemberGlut WordPress plugin prior to version 1.1.5 is vulnerable due to inadequate validation of user roles during front-end registration, enabling unauthenticated users to create accounts with arbitrary roles, including administrator. This flaw poses a critical risk, as it can lead to complete site compromise and unauthorized access to sensitive data. WordPress site administrators using this plugin should prioritize immediate updates to mitigate this severe security threat.

CVE
CVE-2026-12394
Severity
CRITICAL
CVSS
9.8
EPSS
1.49%
WordPress

Original NVD Description

The MemberGlut WordPress plugin before 1.1.5 does not validate the role chosen during front-end registration, allowing unauthenticated users to register an account with an arbitrary role, including administrator, leading to full site compromise.