CyberRota Analysis
AI-GeneratedThe My Login WordPress plugin prior to version 7.2.0 is vulnerable in multisite installations, where it fails to enforce the network's registration settings, allowing subscribers and unauthenticated users to create new sites with administrative privileges. This could lead to unauthorized access and control over new sites, posing a risk to the integrity and security of the WordPress network. WordPress administrators, particularly those managing multisite environments, should prioritize updating to the latest version to mitigate this risk.
Original NVD Description
The My Login WordPress plugin before 7.2.0 does not enforce the network's registration setting when processing site signups on multisite installations, allowing users with a subscriber account, and unauthenticated users on some networks, to create new sites and be granted administrator over them.