Independent cybersecurity news and intelligence
HomeSourcesRSS
Cybersecurity News. Source-grounded Intelligence.
Back to newsroom
VulnerabilitiesCyberDeltaForce Newsroom

CVE-2026-15451: The MemberPress Corporate Accounts plugin for WordPress is vulnerable to Privilege Escalation in vulnerability

A security weakness in The MemberPress Corporate Accounts plugin for WordPress is vulnerable to Privilege Escalation in is being tracked as CVE-2026-15451. The MemberPress Corporate Accounts plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1 5 39.

NIST NVDSep 12, 2026, 1:16 PM UTC3 min readCVE-2026-15451
IN 30 SECONDS

What you need to know

What happenedSource reporting

A security weakness in The MemberPress Corporate Accounts plugin for WordPress is vulnerable to Privilege Escalation in is being tracked as CVE-2026-15451. The MemberPress Corporate Accounts plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1 5 39.

Who is affectedSource reporting

The affected release boundary in the available advisory material is up to, and including, 1.5.39. This is due to The MemberPress Corporate Accounts plugin for WordPress; teams should compare that boundary with the versions actually running in production.

Exploitation statusCDF assessment

No active exploitation was identified in the current reporting reviewed.

Why it mattersSource reporting

The important point is that running an affected version of The MemberPress Corporate Accounts plugin for WordPress is vulnerable to Privilege Escalation in creates exposure, while an actual compromise still depends on whether the attacker can reach the trigger conditions described above.

What to do nowCDF guidance

Inventory the affected product deployments and confirm whether the affected component and vulnerable release are present.

THE NEWS

What happened

Verified reporting in clear, practical language.

A security weakness in The MemberPress Corporate Accounts plugin for WordPress is vulnerable to Privilege Escalation in is being tracked as CVE-2026-15451. The MemberPress Corporate Accounts plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 1 5 39. The affected release boundary in the available advisory material is up to, and including, 1.5.39. This is due to The MemberPress Corporate Accounts plugin for WordPress; teams should compare that boundary with the versions actually running in production.

The flaw is best understood as a privilege-escalation weakness, rather than simply as a CVE number or severity score. If the published conditions are met, the security consequence is higher privileges than intended. CVE-2026-15451 currently carries a HIGH 8 8 severity signal in the retained vulnerability data.

The important point is that running an affected version of The MemberPress Corporate Accounts plugin for WordPress is vulnerable to Privilege Escalation in creates exposure, while an actual compromise still depends on whether the attacker can reach the trigger conditions described above. This is due to The MemberPress Corporate Accounts plugin for WordPress as affected versions.

The affected versions identified in the advisory are up to, and including, 1 5 39. The available advisory information identifies up to, and including, 1 5 39. The issue currently carries a HIGH 8 8 severity signal in the CyberDeltaForce record.

The current severity signal is HIGH 8 8. The operational question is not simply the severity score, but whether the affected component is deployed, reachable, business-critical and protected by compensating controls. Real risk depends on exposure, exploitability, compensating controls and the importance of the affected asset—not the CVSS number alone.

This is due to a mass assignment vulnerability in the 'add_sub_account_user' function that passes the raw 'userdata' array to 'wp_insert_user' without filtering dangerous keys like role or ID. Inventory the affected product deployments and confirm whether the affected component and vulnerable release are present. Apply the vendor patch or mitigation for CVE-2026-15451 and validate the affected path after remediation.

The current source set does not report active exploitation of CVE-2026-15451; that status should be monitored rather than treated as proof that exploitation is impossible. The most useful validation after remediation is to confirm that the vulnerable path no longer permits the reported behavior and that the deployed release matches the vendor's corrected version.

So far, researchers have not reported exploitation, but that can change as vendor, government or threat-intelligence reporting develops.

REFERENCES

Reference sources

CYBERDELTAFORCE INTELLIGENCE

Reporting ends here. The sections below are CyberDeltaForce analysis and defender-focused interpretation.

DEFENDER ACTIONS

What security teams should do now

  • Inventory the affected product deployments and confirm whether the affected component and vulnerable release are present.
  • Apply the vendor patch or mitigation for CVE-2026-15451 and validate the affected path after remediation.
OPEN QUESTIONS

What is not yet confirmed

  • So far, researchers have not reported exploitation, but that can change as vendor, government or threat-intelligence reporting develops.
Continue the story

Related Cybersecurity Coverage

More cybersecurity news
CyberDeltaForce publication standards