Review
MemberGlut
CVE published 2026-07-27
CVE-2026-12394
The MemberGlut WordPress plugin before 1.1.5 has a critical vulnerability that allows unauthenticated users to register an account with an arbitrary role, including administrator. This oversight during front-end registration can lead to full site compromise. The vulnerability has a high impact on the confidentiality, integrity, and availability of the WordPress site. Users of the MemberGlut WordPress plug [truncated]