Executive brief
MemberHero is a WordPress plugin that manages user registration on websites. The plugin fails to properly validate which account fields users can set during registration, allowing attackers to register new accounts with administrative privileges without authentication. This leads to complete compromise of the affected website, allowing attackers to modify content, steal data, and take over existing user accounts.
Technical details
The vulnerability is an improper input validation / privilege escalation issue in the frontend registration process. The vulnerable component fails to restrict which account fields (specifically the user role field) can be supplied during unauthenticated registration, allowing attackers to POST arbitrary role values when creating accounts. Version 6.9 attempted to address this but the fix is incomplete; attackers can still bypass role restrictions and obtain administrator access or take over existing accounts. The attack is unauthenticated and network-accessible via the public registration form. No fully patched version is currently available; the vendor recommends deactivating the plugin or disabling public registration as mitigation.
Affected products
- MemberHero MemberHero through 6.9
Timeline
- 2026-08-27: disclosed
- 2026-08-29: advisory