Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-2qr9-rw6c-j2jw

Опубликовано: 27 июл. 2026
Источник: github
Github: Не прошло ревью
CVSS3: 9.8

Описание

The MemberGlut WordPress plugin before 1.1.5 does not validate the role chosen during front-end registration, allowing unauthenticated users to register an account with an arbitrary role, including administrator, leading to full site compromise.

The MemberGlut WordPress plugin before 1.1.5 does not validate the role chosen during front-end registration, allowing unauthenticated users to register an account with an arbitrary role, including administrator, leading to full site compromise.

EPSS

Процентиль: 20%
0.00277
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-269

Связанные уязвимости

CVSS3: 9.8
nvd
10 дней назад

The MemberGlut WordPress plugin before 1.1.5 does not validate the role chosen during front-end registration, allowing unauthenticated users to register an account with an arbitrary role, including administrator, leading to full site compromise.

EPSS

Процентиль: 20%
0.00277
Низкий

9.8 Critical

CVSS3

Дефекты

CWE-269