CVE-2026-10522
moderateUnauthenticated Privilege Escalation in MemberHero WordPress Plugin (through 6.9)
The MemberHero WordPress membership plugin does not restrict which account fields can be supplied during its frontend registration process, so an unauthenticated attacker can register a new user and assign themselves an arbitrary role, including Administrator, which permits full site takeover. The flaw can also be used to take over existing accounts, not just create new ones. Any WordPress site running MemberHero through version 6.9 with the plugin active is affected, though sites with public registration disabled or registration endpoints restricted have limited exposure. Version 6.9 was advertised as fixing the issue, but the fix is incomplete and the current version remains exploitable, with no fully patched release available at the time of the advisory. No public proof-of-concept or confirmed in-the-wild exploitation is known, and the low EPSS (0.3%, 27th percentile) suggests exploitation is not yet widespread.
What to do: Deactivate and remove MemberHero (all versions through 6.9) until a release that fully resolves the issue is published, since the 6.9 fix is incomplete. If the plugin must stay active, disable public registration or restrict access to the registration endpoint, and monitor the site for unexpected administrator accounts. Audit the existing administrator list for accounts created through the plugin's registration form.
| MemberHero WordPress plugin | through 6.9 (inclusive; the 6.9 fix is incomplete and no fully fixed version is available) |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
The MemberHero WordPress plugin through 6.9 does not restrict which account fields can be supplied during its frontend registration process, allowing unauthenticated attackers to register a new user with an arbitrary role, including Administrator, leading to a full site takeover. Version 6.9 is advertised as resolving this issue, but the fix is incomplete and the current version remains exploitable by unauthenticated attackers to obtain administrator access and to take over existing accounts. No version that fully addresses the issue is available at the time of this advisory. Mitigation: deactivate and remove the MemberHero WordPress plugin through 6.9 until a version that fully resolves this issue is released. If the MemberHero WordPress plugin through 6.9 must stay active, disable public registration, restrict access to the registration functionality, and monitor the site for unexpected administrator accounts.
- Ecosystems
- WordPress
- Weakness
- CWE-269
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
In the news0 stories
No ingested article mentions this CVE yet.