What is CVE-2026-12394?
The MemberGlut WordPress plugin before version 1.1.5 fails to validate the role during front-end registration. This allows unauthenticated users to register with arbitrary roles, including administrator, leading to full site compromise. Immediate update to the latest version is required.
Azərbaycanca: MemberGlut WordPress plugin-inin 1.1.5-dən əvvəlki versiyalarında qeydiyyat zamanı rol yoxlanılmır. Bu, autentifikasiya olunmamış istifadəçilərə administrator daxil olmaqla ixtiyari rolla hesab yaratmağa imkan verir. Dərhal plugin-i son versiyaya yeniləməlisiniz.
Related CVEs
link basis: same weakness class CWE-269
FAQ2
Which versions of the MemberGlut plugin are affected by CVE-2026-12394?
All versions of the MemberGlut plugin before 1.1.5 are affected by this vulnerability.
What is the potential impact of CVE-2026-12394?
This vulnerability allows unauthenticated users to register with arbitrary roles, including administrator, leading to full site compromise.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.