CVE-2026-12394 - MemberGlut < 1.1.5 - Unauthenticated Privilege Escalation to Administrator
CVE ID :CVE-2026-12394
Published : July 27, 2026, 6 a.m. | 51 minutes ago
Description :The MemberGlut WordPress plugin before 1.1.5 does not validate the role chosen during front-end registration, allowing unauthenticated users to register an account with an arbitrary role, including administrator, leading to full site compromise.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...
Published : July 27, 2026, 6 a.m. | 51 minutes ago
Description :The MemberGlut WordPress plugin before 1.1.5 does not validate the role chosen during front-end registration, allowing unauthenticated users to register an account with an arbitrary role, including administrator, leading to full site compromise.
Severity: 0.0 | NA
Visit the link for more details, such as CVSS details, affected products, timeline, and more...