GHSA-2qr9-rw6c-j2jwunknown

The MemberGlut WordPress plugin before 1.1.5 does not validate the role chosen during front-end...

Published
July 27, 2026
Last Modified
July 27, 2026

🔗 CVE IDs covered (1)

📋 Description

The MemberGlut WordPress plugin before 1.1.5 does not validate the role chosen during front-end registration, allowing unauthenticated users to register an account with an arbitrary role, including administrator, leading to full site compromise.

🔗 References (3)