CVE-2026-81583 The My Login WordPress plugin before 7.2.0 does not… — CVE Notify — TG.ME

🚨 CVE-2026-81583
The My Login WordPress plugin before 7.2.0 does not enforce the network's registration setting when processing site signups on multisite installations, allowing users with a subscriber account, and unauthenticated users on some networks, to create new sites and be granted administrator over them.

🎖@cveNotify
WPScan
Theme My Login 7.0 - 7.1.15 - Subscriber+ Unauthorised Multisite Site Creation and Privilege Escalation
See details on Theme My Login 7.0 - 7.1.15 - Subscriber+ Unauthorised Multisite Site Creation and Privilege Escalation CVE 2026-81583. View the latest Plugin Vulnerabilities on WPScan.
September 2, 2026 36