PatchSiren

MemberGlut CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

Review MemberGlut CVE published 2026-07-27

CVE-2026-12394

The MemberGlut WordPress plugin before 1.1.5 has a critical vulnerability that allows unauthenticated users to register an account with an arbitrary role, including administrator. This oversight during front-end registration can lead to full site compromise. The vulnerability has a high impact on the confidentiality, integrity, and availability of the WordPress site. Users of the MemberGlut WordPress plug [truncated]