CVE-2026-12394 PUBLISHED

MemberGlut < 1.1.5 - Unauthenticated Privilege Escalation to Administrator

Assigner: WPScan
Reserved: 16.06.2026 Published: 27.07.2026 Updated: 27.07.2026

The MemberGlut WordPress plugin before 1.1.5 does not validate the role chosen during front-end registration, allowing unauthenticated users to register an account with an arbitrary role, including administrator, leading to full site compromise.

Product Status

Vendor Unknown
Product MemberGlut
Versions Default: unaffected
  • affected from 0 to 1.1.5 (excl.)

Credits

  • moonge finder
  • WPScan coordinator

References

Problem Types

  • CWE-269 Improper Privilege Management CWE