PatchSiren

My Login CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

MEDIUM My Login CVE published 2026-09-02

CVE-2026-81583

The My Login WordPress plugin before 7.2.0 does not enforce the network's registration setting when processing site signups on multisite installations, allowing users with a subscriber account, and unauthenticated users on some networks, to create new sites and be granted administrator over them. This vulnerability has significant implications for WordPress multisite administrators and users with subscrib [truncated]