CVE-2026-10522
Received Received - Intake

Unauthenticated Privilege Escalation in MemberHero WordPress Plugin

Vulnerability report for CVE-2026-10522, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-29

Last updated on: 2026-08-29

Assigner: WPScan

Description

The MemberHero WordPress plugin through 6.9 does not restrict which account fields can be supplied during its frontend registration process, allowing unauthenticated attackers to register a new user with an arbitrary role, including Administrator, leading to a full site takeover. Version 6.9 is advertised as resolving this issue, but the fix is incomplete and the current version remains exploitable by unauthenticated attackers to obtain administrator access and to take over existing accounts. No version that fully addresses the issue is available at the time of this advisory. Mitigation: deactivate and remove the MemberHero WordPress plugin through 6.9 until a version that fully resolves this issue is released. If the MemberHero WordPress plugin through 6.9 must stay active, disable public registration, restrict access to the registration functionality, and monitor the site for unexpected administrator accounts.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-29
Last Modified
2026-08-29
Generated
2026-08-29
AI Q&A
2026-08-29
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
memberhero simple_user_registration to 6.9 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The MemberHero WordPress plugin through version 6.9 has an unauthenticated privilege escalation vulnerability. Attackers can register a new user with any role, including Administrator, allowing full site takeover. Version 6.9 claims to fix this but the patch is incomplete, leaving the vulnerability still exploitable.

Detection Guidance

Check for unexpected administrator accounts or unusual user registrations. Inspect the MemberHero plugin version via WordPress admin panel or database. Look for unauthorized role assignments in user management.

Impact Analysis

An attacker could exploit this to gain full control of your WordPress site by creating an administrator account. This could lead to data theft, malware installation, or defacement of your website.

Mitigation Strategies

Deactivate and remove the MemberHero plugin through 6.9. If removal is not possible, disable public registration, restrict access to registration functionality, and monitor for unexpected administrator accounts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-10522. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart