Description
The MemberHero WordPress plugin through 6.9 does not restrict which account fields can be supplied during its frontend registration process, allowing unauthenticated attackers to register a new user with an arbitrary role, including Administrator, leading to a full site takeover.

Version 6.9 is advertised as resolving this issue, but the fix is incomplete and the current version remains exploitable by unauthenticated attackers to obtain administrator access and to take over existing accounts. No version that fully addresses the issue is available at the time of this advisory.

Mitigation: deactivate and remove the MemberHero WordPress plugin through 6.9 until a version that fully resolves this issue is released. If the MemberHero WordPress plugin through 6.9 must stay active, disable public registration, restrict access to the registration functionality, and monitor the site for unexpected administrator accounts.
Published: 2026-08-29
Score: n/a
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The MemberHero WordPress plugin allows any visitor to submit registration data via its frontend form without verifying the requested user role. If the role field is set to Administrator, the new account is granted full site control. This flaw enables attackers to elevate privileges without authentication, resulting in complete site takeover, data exfiltration, and destructive changes.

Affected Systems

The Vulnerability affects all instances of the MemberHero plugin version 6.9 and earlier. No secure release that fully addresses the issue is available yet.

Risk and Exploitability

Attackers can exploit the flaw by simply accessing the plugin’s public registration page and posting credentials with the role set to Administrator. No credentials or network access restrictions are required. The vulnerability is persistent until a fully patched version is installed. While EPSS is not available and the issue is not in the CISA KEV catalog, the inherent risk of unrestricted administrative access is high and warrants immediate action.

Generated by OpenCVE AI on August 29, 2026 at 07:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Deactivate and uninstall the MemberHero plugin version 6.9 or earlier.
  • If the plugin must remain active, disable public registration and restrict registration functionality to trusted users.
  • Regularly audit the WordPress admin area for unexpected new Administrator accounts and monitor all registration activity.
  • Monitor the vendor’s release notes for a corrective patch and update the plugin to the latest secure version as soon as it becomes available.

Generated by OpenCVE AI on August 29, 2026 at 07:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 29 Aug 2026 08:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284

Sat, 29 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
First Time appeared Memberhero
Memberhero member Hero
Wordpress
Wordpress wordpress
Vendors & Products Memberhero
Memberhero member Hero
Wordpress
Wordpress wordpress

Sat, 29 Aug 2026 06:15:00 +0000

Type Values Removed Values Added
Description The MemberHero WordPress plugin through 6.9 does not restrict which account fields can be supplied during its frontend registration process, allowing unauthenticated attackers to register a new user with an arbitrary role, including Administrator, leading to a full site takeover. Version 6.9 is advertised as resolving this issue, but the fix is incomplete and the current version remains exploitable by unauthenticated attackers to obtain administrator access and to take over existing accounts. No version that fully addresses the issue is available at the time of this advisory. Mitigation: deactivate and remove the MemberHero WordPress plugin through 6.9 until a version that fully resolves this issue is released. If the MemberHero WordPress plugin through 6.9 must stay active, disable public registration, restrict access to the registration functionality, and monitor the site for unexpected administrator accounts.
Title Simple User Registration <= 6.9 - Unauthenticated Privilege Escalation to Administrator
References

Subscriptions

Memberhero Member Hero
Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-08-29T06:00:18.586Z

Reserved: 2026-06-01T08:55:33.674Z

Link: CVE-2026-10522

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-29T06:16:57.717

Modified: 2026-08-29T06:16:57.717

Link: CVE-2026-10522

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-29T08:00:05Z

Weaknesses