Impact
The MemberGlut plugin for WordPress allows an unauthenticated user to register an account through its front‑end registration page without validating the role selected. By choosing the administrator role, an attacker can obtain full site control, giving them the ability to manipulate content, install additional plugins, and access all administrative functions. This flaw enables an attacker to compromise the entire WordPress installation, leading to complete loss of confidentiality, integrity, and availability.
Affected Systems
Any WordPress site running MemberGlut versions prior to 1.1.5 is affected, regardless of the WordPress core version. The vulnerability applies to all installations where the front‑end registration feature is enabled and role selection is available during sign‑up.
Risk and Exploitability
The CVSS score of 9.8 reflects a high severity critical vulnerability. The EPSS score of 0.00277 indicates a very low probability of exploitation, although the flaw remains straightforward for unauthenticated users. As the vulnerability is not listed in the CISA KEV catalog, it may not yet be widely reported, yet the impact and vector remain severe. The likely attack vector is via the public registration page of a WordPress site, requiring no client‑side code execution or complex prerequisites.
OpenCVE Enrichment