Impact
The MemberHero WordPress plugin allows any visitor to submit registration data via its frontend form without verifying the requested user role. If the role field is set to Administrator, the new account is granted full site control. This flaw enables attackers to elevate privileges without authentication, resulting in complete site takeover, data exfiltration, and destructive changes.
Affected Systems
The Vulnerability affects all instances of the MemberHero plugin version 6.9 and earlier. No secure release that fully addresses the issue is available yet.
Risk and Exploitability
Attackers can exploit the flaw by simply accessing the plugin’s public registration page and posting credentials with the role set to Administrator. No credentials or network access restrictions are required. The vulnerability is persistent until a fully patched version is installed. While EPSS is not available and the issue is not in the CISA KEV catalog, the inherent risk of unrestricted administrative access is high and warrants immediate action.
OpenCVE Enrichment