๐Ÿ” CVE Alert

CVE-2026-94235

UNKNOWN 0.0

Simple User Registration <= 6.9 - Subscriber+ Arbitrary Email Sending via wpr_send_email_to_user

CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th

The MemberHero WordPress plugin through 6.9 does not perform any capability or nonce check on one of its AJAX actions, allowing any authenticated user, such as a subscriber, to make the site send arbitrary HTML emails to arbitrary recipients from its own mail system, which can be abused to relay phishing carrying the site's identity and domain reputation.

Vendor unknown
Product memberhero
Published Oct 11, 2026
Stay Ahead of the Next One

Get instant alerts for unknown memberhero

Be the first to know when new unknown vulnerabilities affecting unknown memberhero are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / MemberHero
0 โ‰ค 6.9

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/be83535f-9224-4dfc-ada9-9e688e703717/

Credits

Yaswanth Reddy Sunkara WPScan