Impact
The MemberPress Corporate Accounts plugin for WordPress contains a mass assignment flaw in the add_sub_account_user function. Raw user data supplied by the attacker is passed directly to wp_insert_user without filtering dangerous keys such as role or ID. This flaw allows an authenticated user with subscriber-level access or higher, who also has a corporate account, to create new administrator accounts or hijack existing administrators by overriding their email addresses.
Affected Systems
All installations of the MemberPress Corporate Accounts plugin for WordPress up to and including version 1.5.39 are affected. Users who possess a corporate account and have at least subscriber privileges can exercise the vulnerable sub‑account creation feature.
Risk and Exploitability
The CVSS score of 8.8 indicates a high severity vulnerability. No EPSS score is available, so the likelihood of exploitation is not quantified, but the known lack of a KEV listing and the clear exploitation path through an authenticated user suggest that the risk remains significant. An attacker can bypass normal role restrictions via mass assignment and gain administrative control in the WordPress environment.
OpenCVE Enrichment