MEDIUM
My Login
CVE published 2026-09-02
CVE-2026-81583
The My Login WordPress plugin before 7.2.0 does not enforce the network's registration setting when processing site signups on multisite installations, allowing users with a subscriber account, and unauthenticated users on some networks, to create new sites and be granted administrator over them. This vulnerability has significant implications for WordPress multisite administrators and users with subscrib [truncated]