Retour à la veille

CVE-2026-12394

Publié : 27 juillet 2026
Modifié : 27 juillet 2026
Lien officiel NVD

Description détaillée

The MemberGlut WordPress plugin before 1.1.5 does not validate the role chosen during front-end registration, allowing unauthenticated users to register an account with an arbitrary role, including administrator, leading to full site compromise.

Références et Patchs