CVE-2026-81583: Unknown Theme My Login
Medium severity, CVSS 5.4. EPSS: 0.3% chance of exploitation in the next 30 days.
The My Login WordPress plugin before 7.2.0 does not enforce the network's registration setting when processing site signups on multisite installations, allowing users with a subscriber account, and unauthenticated users on some networks, to create new sites and be granted administrator over them.
Affected products
- Unknown Theme My Login: from 7.0, before 7.2.0 (fixed in 7.2.0)
Published 2026-09-02. Last modified 2026-09-03.