CVE-2026-16310
Received Received - Intake

Insecure Direct Object Reference in MemberDash WordPress Plugin

Vulnerability report for CVE-2026-16310, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-06

Last updated on: 2026-09-06

Assigner: Wordfence

Description

The MemberDash plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.8.5 via the 'id' parameter due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to change the password of any WordPress user, including administrators, by supplying an arbitrary user ID during registration, and take over their account without any notification sent to the victim.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-06
Last Modified
2026-09-06
Generated
2026-09-06
AI Q&A
2026-09-06
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
memberdash memberdash to 1.8.5 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-639 The system's authorization functionality does not prevent one user from gaining access to another user's data or record by modifying the key value identifying the data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an Insecure Direct Object Reference (IDOR) in the MemberDash WordPress plugin. It allows unauthenticated attackers to change the password of any WordPress user, including administrators, by exploiting a missing validation on the 'id' parameter during registration. Attackers can supply an arbitrary user ID to take over accounts without the victim being notified.

Detection Guidance

To detect this vulnerability, inspect WordPress sites using the MemberDash plugin version 1.8.5 or lower. Check for unauthorized password changes or suspicious user registrations with arbitrary user IDs. Review server logs for unusual activity related to the 'id' parameter in registration requests.

Impact Analysis

If you use the MemberDash plugin, attackers could hijack your WordPress account, including admin accounts, by changing passwords. This could lead to unauthorized access to your site, data theft, or malicious actions performed under your identity. Users with sensitive roles are at higher risk.

Compliance Impact

This vulnerability could lead to unauthorized access to user data, violating GDPR's data protection principles and HIPAA's security requirements. If personal or health data is exposed or altered, it may result in non-compliance, legal penalties, or reputational damage for organizations handling such data.

Mitigation Strategies

Immediately update the MemberDash plugin to the latest version beyond 1.8.5. If an update is unavailable, disable the plugin temporarily. Review all user accounts for unauthorized changes and reset passwords for affected users, including administrators.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16310. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart