CVE-2026-81583
Theme My Login 7.0 - 7.1.15 - Subscriber+ Unauthorised Multisite Site Creation and Privilege Escalation
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The My Login WordPress plugin before 7.2.0 does not enforce the network's registration setting when processing site signups on multisite installations, allowing users with a subscriber account, and unauthenticated users on some networks, to create new sites and be granted administrator over them.
| Vendor | unknown |
| Product | theme my login |
| Published | Sep 2, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown theme my login
Be the first to know when new unknown vulnerabilities affecting unknown theme my login are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / Theme My Login
7.0 < 7.2.0
References
Credits
Jakub Herman WPScan