← Back to overview

The MemberDash plugin for WordPress contains a critical Insecure Direct Object Reference (IDOR) vulnerability in all versions up to and including 1.8.5. The flaw exists in the 'id' parameter due to missing validation on a user-controlled key during registration. Unauthenticated attackers can exploit this vulnerability to change the password of any WordPress user, including administrators, by supplying an arbitrary user ID. This allows complete account takeover without any notification being sent to the victim. The vulnerability requires no authentication, making it trivially exploitable by remote attackers. The impact is severe as it enables full compromise of WordPress sites running the affected plugin version. Site administrators are advised to update to a patched version immediately.

Affected products

  • MemberDash WordPress Plugin 1.8.5 and below

Related CVE's

  • CVE-2026-16310

Categories

  • Identity & Access
  • Web Technologies