CVE-2026-94235
Simple User Registration <= 6.9 - Subscriber+ Arbitrary Email Sending via wpr_send_email_to_user
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
The MemberHero WordPress plugin through 6.9 does not perform any capability or nonce check on one of its AJAX actions, allowing any authenticated user, such as a subscriber, to make the site send arbitrary HTML emails to arbitrary recipients from its own mail system, which can be abused to relay phishing carrying the site's identity and domain reputation.
| Vendor | unknown |
| Product | memberhero |
| Published | Oct 11, 2026 |
Stay Ahead of the Next One
Get instant alerts for unknown memberhero
Be the first to know when new unknown vulnerabilities affecting unknown memberhero are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
Affected Versions
Unknown / MemberHero
0 โค 6.9
References
Credits
Yaswanth Reddy Sunkara WPScan