CVE-2026-94235 PUBLISHED

Simple User Registration <= 6.9 - Subscriber+ Arbitrary Email Sending via wpr_send_email_to_user

Assigner: WPScan
Reserved: 21.09.2026 Published: 11.10.2026 Updated: 11.10.2026

The MemberHero WordPress plugin through 6.9 does not perform any capability or nonce check on one of its AJAX actions, allowing any authenticated user, such as a subscriber, to make the site send arbitrary HTML emails to arbitrary recipients from its own mail system, which can be abused to relay phishing carrying the site's identity and domain reputation.

Product Status

Vendor Unknown
Product MemberHero
Versions Default: unknown
  • affected from 0 to 6.9 (incl.)

Credits

  • Yaswanth Reddy Sunkara finder
  • WPScan coordinator

References

Problem Types

  • CWE-862 Missing Authorization CWE