CRITICAL 9.8 CVE-2026-16310 Published 6 Sept 2026

WordPress MemberDash Plugin Password Change Vulnerability

Worried this affects one of your servers?

The MemberDash plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.8.5.

An unauthenticated attacker can change the password of any WordPress user, including administrators, by supplying an arbitrary user ID during registration.

This allows attackers to take over user accounts without any notification sent to the victim.

Reference: CVE-2026-16310 on NVD

← Back to Security News