VYPR

MemberHero

by WordPress

CVEs (1)

  • CVE-2026-10522Aug 29, 2026
    risk 0.00cvss epss

    The MemberHero WordPress plugin through 6.9 does not restrict which account fields can be supplied during its frontend registration process, allowing unauthenticated attackers to register a new user with an arbitrary role, including Administrator, leading to a full site…