Privilege Escalation Vulnerability in MemberPress Corporate Accounts for WordPress
CVE-2026-15451

8.8HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
12 September 2026

What is CVE-2026-15451?

The MemberPress Corporate Accounts plugin for WordPress is exposed to a privilege escalation issue in versions up to and including 1.5.39. The vulnerability arises from a mass assignment flaw in the 'add_sub_account_user' function, where raw input from the 'userdata' array is passed to the 'wp_insert_user' without proper filtering of sensitive keys such as role or ID. This oversight enables authenticated attackers with subscriber-level access and above, who possess a corporate account, to create new administrator accounts or compromise existing ones by altering their email addresses. While a partial patch was issued in version 1.5.39, users are advised to assess their current installation for potential risks.

Affected Version(s)

MemberPress Corporate Accounts 0 <= 1.5.39

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

andrea bocchetti
.