CRITICAL
9.8 CVE-2026-10522 Published 29 Aug 2026
WordPress MemberHero Plugin Admin Takeover Bug
Worried this affects one of your servers?
The MemberHero WordPress plugin, up to version 6.9, has a critical security flaw. It does not validate user roles during the frontend registration process, allowing unauthenticated attackers to register as an administrator and take over the entire site.
Even though version 6.9 claims to fix this issue, the fix is incomplete, and the current version remains vulnerable. There is no fully patched version available yet.
Mitigation: Deactivate and remove the plugin until a full fix is released. If the plugin must stay active, disable public registration, restrict access to registration, and monitor for unexpected admin accounts.
Reference: CVE-2026-10522 on NVD
← Back to Security News