Unauthorized Role Assignment in MemberHero Plugin for WordPress
CVE-2026-10522
Key Information:
- Vendor
WordPress
- Status
- Vendor
- CVE Published:
- 29 August 2026
Badges
What is CVE-2026-10522?
The MemberHero plugin for WordPress, up to version 6.9, suffers from a serious security issue where it fails to properly restrict the fields that can be provided during the frontend registration process. This oversight allows unauthorized users to create new accounts with arbitrary roles, including that of an Administrator. Consequently, attackers can gain unauthorized access, potentially leading to a complete site takeover. Although version 6.9 was released to address the problem, the fix is only partial, leaving the vulnerability exploitable. No secure version is currently available, thereby making immediate action necessary. It is advised to deactivate and remove the plugin until a fully patched version is released, or to at least disable public registrations and monitor user activity closely.
Affected Version(s)
MemberHero 0 <= 6.9
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.