CVE-2026-81583
UNKNOWN
NVD
CVSS Score
0
Severity
UNKNOWN
Published
Sep 02, 2026
Vendor
unknown
Description
The My Login WordPress plugin before 7.2.0 does not enforce the network's registration setting when processing site signups on multisite installations, allowing users with a subscriber account, and unauthenticated users on some networks, to create new sites and be granted administrator over them.