MEDIUM
jfarthing84
CVE published 2026-09-05
CVE-2026-83628
The Theme My Login plugin for WordPress has a Missing Authorization vulnerability in versions up to 7.1.15 on Multisite installations. This allows authenticated attackers with Subscriber-level access and above to bypass the configured registration policy and create a new subsite with Administrator role. The vulnerability arises from the `tml_ms_signup_handler()` function's `gimmeanotherblog` branch failin [truncated]