Executive brief
Theme My Login is a WordPress plugin used to customize user login and registration forms on WordPress multisite networks. The plugin fails to enforce the network administrator's registration restrictions, allowing subscribers and unauthenticated users to create new sites and gain administrator privileges over them. This can lead to unauthorized site creation, data manipulation, and compromise of network integrity.
Technical details
The vulnerability is an authorization bypass (CWE-269) in the plugin's multisite signup handling. The plugin processes site signup requests through a custom action handler that does not properly validate the network's registration settings before creating new sites. Attack vectors include: (1) a subscriber sending a POST request with signup parameters to bypass registration restrictions and create a site with administrator access, and (2) an unauthenticated user exploiting this when the network allows "logged in users may register" by providing an email address that receives an activation link, allowing account creation and site provisioning without authentication. No user interaction is required beyond sending HTTP requests. The vulnerability affects versions 7.0 through 7.1.15 and is fixed in version 7.2.0.
Affected products
- WPScan Theme My Login 7.0 through 7.1.15
Timeline
- 2026-08-31: disclosed
- 2026-09-02: patched: Fixed in version 7.2.0