SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-81583

MEDIUM · CVSS 5.4 EPSS 0.18%

Source: NVD + CISA KEV + EPSS · Published 2026-09-02 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The My Login WordPress plugin prior to version 7.2.0 is vulnerable in multisite installations, where it fails to enforce the network's registration settings, allowing subscribers and unauthenticated users to create new sites with administrative privileges. This could lead to unauthorized access and control over new sites, posing a risk to the integrity and security of the WordPress network. WordPress administrators, particularly those managing multisite environments, should prioritize updating to the latest version to mitigate this risk.

CVE
CVE-2026-81583
Severity
MEDIUM
CVSS
5.4
EPSS
0.18%
WordPress

Original NVD Description

The My Login WordPress plugin before 7.2.0 does not enforce the network's registration setting when processing site signups on multisite installations, allowing users with a subscriber account, and unauthenticated users on some networks, to create new sites and be granted administrator over them.