Insecure Direct Object Reference Vulnerability in MemberDash Plugin by WordPress
CVE-2026-16310
9.8CRITICAL
What is CVE-2026-16310?
The MemberDash plugin for WordPress contains a vulnerability that allows unauthenticated attackers to exploit an insecure direct object reference via the 'id' parameter. Due to insufficient validation of user-controlled input, attackers can manipulate arbitrary user IDs during the registration process. This flaw enables them to change the passwords of any WordPress users, including administrators, effectively gaining unauthorized access to their accounts without alerting the victims.
Affected Version(s)
MemberDash 0 <= 1.8.5