Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-10522— Simple User Registration <= 6.9 - Unauthenticated Privilege Escalation to Administrator

Quick assessment

Affected
Unknown MemberHero
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

MemberHero WordPress 插件(版本 6.9 及之前)未对前端注册过程中可提交的账户字段进行限制,这使得未认证的 attackers 能够以任意角色(包括“管理员”角色)注册新用户,从而导致对整个网站的完全接管。 虽然 6.9 版本声称已修复该问题,但该修复并不完整,当前版本仍可被未认证的 attackers 利用,以获取管理员权限并接管现有账户。截至本公告发布时,尚无一个能完全解决此问题的版本可用。 缓解措施:在发布完全解决此问题的新版本之前,建议停用并移除 MemberHero WordPres

AI Predicted 9.8 Difficulty: Trivial

Possible ATT&CK Techniques 2 AI

T1078 · Valid Accounts T1099
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-10522

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Simple User Registration <= 6.9 - Unauthenticated Privilege Escalation to Administrator
Source: CVE Program / CVE List V5
Vulnerability Description
The MemberHero WordPress plugin through 6.9 does not restrict which account fields can be supplied during its frontend registration process, allowing unauthenticated attackers to register a new user with an arbitrary role, including Administrator, leading to a full site takeover. Version 6.9 is advertised as resolving this issue, but the fix is incomplete and the current version remains exploitable by unauthenticated attackers to obtain administrator access and to take over existing accounts. No version that fully addresses the issue is available at the time of this advisory. Mitigation: deactivate and remove the MemberHero WordPress plugin through 6.9 until a version that fully resolves this issue is released. If the MemberHero WordPress plugin through 6.9 must stay active, disable public registration, restrict access to the registration functionality, and monitor the site for unexpected administrator accounts.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Unknown MemberHero 0 ~ 6.9 -

II. Public POCs for CVE-2026-10522

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-10522

登录查看更多情报信息。

Other References for CVE-2026-10522 (1)

Same Patch Batch · Unknown · 2026-08-29 · 26 CVEs total

CVE-2026-76586 BookingPress 1.5.6 - 1.6.2 - Unauthenticated Booking Price Manipulation via PayPal Payment
CVE-2026-16061 Rest Routes <= 5.5.5 - Unauthenticated SQLi via custom-tables/tables/{table_name}
CVE-2026-16947 Total Processing Card Payments for WooCommerce <= 7.3 - Unauthenticated SSRF leading to Pa
CVE-2026-16600 SmartAIPress <= 1.2.0 - Subscriber+ Server-Side Request Forgery via smartaipress_openai_up
CVE-2026-16259 Uix UserCenter <= 1.0.3 - Unauthenticated Privilege Escalation
CVE-2026-17520 Newsletters < 4.17 - Unauthenticated API Access via Predictable API Key
CVE-2026-17522 Newsletters < 4.17 - Arbitrary Plugin Option Update via CSRF
CVE-2026-76546 Profile Builder < 4.0.1 - Contributor+ Stored XSS via Format Date Shortcode
CVE-2026-19430 CatFolders Document Gallery Pro < 2.0.7 - Unauthenticated Missing Authorization via downlo
CVE-2026-18234 MStore API < 4.21.1 - Subscriber+ Arbitrary Order Payment Bypass via Wallet
CVE-2026-18233 MStore API < 4.21.1 - Subscriber+ Arbitrary Order Completion
CVE-2026-76547 Profile Builder < 4.0.1 - Admin+ PHP Object Injection via Import/Export
CVE-2026-76548 Profile Builder < 4.0.1 - Unauthenticated Unpublished Content and Media Modification via F
CVE-2026-81026 MasterStudy LMS < 3.7.40 - Unauthenticated Payment Bypass via PayPal IPN
CVE-2026-77010 HEL Online Classroom: AI-powered Online Classrooms <= 1.0.3 - Unauthenticated Moderator Jo
CVE-2026-77012 Icollect <= 1.0.0 - Unauthenticated Arbitrary File Read, SSRF and Path Traversal File Writ
CVE-2026-77008 HEL Online Classroom: AI-powered Online Classrooms <= 1.0.3 - Unauthenticated Plugin Setti
CVE-2026-77007 HEL Online Classroom: AI-powered Online Classrooms <= 1.0.3 - Unauthenticated BigBlueButto
CVE-2026-80311 Stripe Payment Forms by WP Full Pay < 8.5.5 - Cross-Customer Subscription Cancellation via
CVE-2026-80488 WP Ultimate CSV Importer < 9.0 - Admin+ SQLi via AIOSEO Import Fields

Showing top 20 of 26 CVEs. View all on vendor page &rarr; →

IV. Related Vulnerabilities

V. Comments for CVE-2026-10522

No comments yet


Leave a comment