Privilege Escalation Vulnerability in MemberPress Corporate Accounts for WordPress
CVE-2026-15451
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 12 September 2026
What is CVE-2026-15451?
The MemberPress Corporate Accounts plugin for WordPress is exposed to a privilege escalation issue in versions up to and including 1.5.39. The vulnerability arises from a mass assignment flaw in the 'add_sub_account_user' function, where raw input from the 'userdata' array is passed to the 'wp_insert_user' without proper filtering of sensitive keys such as role or ID. This oversight enables authenticated attackers with subscriber-level access and above, who possess a corporate account, to create new administrator accounts or compromise existing ones by altering their email addresses. While a partial patch was issued in version 1.5.39, users are advised to assess their current installation for potential risks.
Affected Version(s)
MemberPress Corporate Accounts 0 <= 1.5.39