ZeroHour

CVE-2026-10522

moderate

Unauthenticated Privilege Escalation in MemberHero WordPress Plugin (through 6.9)

CVSS 3.1
9.8 critical
EPSS
<1%p27
Published
()
Modified
AI analysis

The MemberHero WordPress membership plugin does not restrict which account fields can be supplied during its frontend registration process, so an unauthenticated attacker can register a new user and assign themselves an arbitrary role, including Administrator, which permits full site takeover. The flaw can also be used to take over existing accounts, not just create new ones. Any WordPress site running MemberHero through version 6.9 with the plugin active is affected, though sites with public registration disabled or registration endpoints restricted have limited exposure. Version 6.9 was advertised as fixing the issue, but the fix is incomplete and the current version remains exploitable, with no fully patched release available at the time of the advisory. No public proof-of-concept or confirmed in-the-wild exploitation is known, and the low EPSS (0.3%, 27th percentile) suggests exploitation is not yet widespread.

What to do: Deactivate and remove MemberHero (all versions through 6.9) until a release that fully resolves the issue is published, since the 6.9 fix is incomplete. If the plugin must stay active, disable public registration or restrict access to the registration endpoint, and monitor the site for unexpected administrator accounts. Audit the existing administrator list for accounts created through the plugin's registration form.

Affected
MemberHero WordPress pluginthrough 6.9 (inclusive; the 6.9 fix is incomplete and no fully fixed version is available)
Estimated exposure
moderateon the order of ~10,000 sites (WordPress.org lists MemberHero with roughly 10,000+ active installs; only sites with public registration enabled are directly… — No install count was provided in the advisory, so this is based on the plugin's publicly listed active-install count on the WordPress.org repository, adjusted downward for sites that do not expose public registration.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

The MemberHero WordPress plugin through 6.9 does not restrict which account fields can be supplied during its frontend registration process, allowing unauthenticated attackers to register a new user with an arbitrary role, including Administrator, leading to a full site takeover. Version 6.9 is advertised as resolving this issue, but the fix is incomplete and the current version remains exploitable by unauthenticated attackers to obtain administrator access and to take over existing accounts. No version that fully addresses the issue is available at the time of this advisory. Mitigation: deactivate and remove the MemberHero WordPress plugin through 6.9 until a version that fully resolves this issue is released. If the MemberHero WordPress plugin through 6.9 must stay active, disable public registration, restrict access to the registration functionality, and monitor the site for unexpected administrator accounts.

Ecosystems
WordPress
Weakness
CWE-269
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.