Security Advisory
CVE-2026-81583
5.4
MEDIUM
Vulnerability Description
The My Login WordPress plugin before 7.2.0 does not enforce the network's registration setting when processing site signups on multisite installations, allowing users with a subscriber account, and unauthenticated users on some networks, to create new sites and be granted administrator over them.
Published Date
September 2, 2026
Official Source
NIST NVD Advisory