Impact
The Theme My Login plugin exhibits a missing authorization flaw that allows any authenticated user with Subscriber-level or higher access to create a new multisite subsite by posting "stage=gimmeanotherblog" to the signup route. The flaw bypasses the network registration policy, resulting in WordPress core assigning the Administrator role on the newly created subsite to the attacking user. The elevated privileges are confined to the subsite level; the attacker’s role on the main network site remains unchanged.
Affected Systems
WordPress Multisite installations using the Theme My Login plugin version 7.1.15 or earlier, maintained by the vendor jfarthing84.
Risk and Exploitability
The CVSS score of 4.3 indicates a moderate severity. EPSS data is unavailable, and the vulnerability is not listed in CISA's KEV catalog. Because the attack vector requires an already authenticated user, exposure is limited to sites where subscribers have sufficient access rights. Successful exploitation grants local administrative rights on the newly created subsite, enabling configuration changes, plugin installations, or other subsite-level actions.
OpenCVE Enrichment