CVE-2026-81583
The My Login WordPress plugin before 7.2.0 does not enforce the network's registration setting when processing site signups on multisite installations, allowing users with a subscriber account, and unauthenticated users on some networks, to create new sites and be granted administrator over them.
- Published Sep 2, 2026
- CVSS 5.4 medium
- 0.3% chance of exploitation in the next 30 days (EPSS)
- A fix is available