{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/memberdash--1.8.5/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:memberdash:memberdash:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-16310"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["MemberDash (\u003c= 1.8.5)"],"_cs_severities":["critical"],"_cs_tags":["web-application","wordpress","idor","account-takeover"],"_cs_type":"advisory","_cs_vendors":["MemberDash"],"content_html":"\u003cp\u003eThe MemberDash plugin for WordPress, in all versions up to and including 1.8.5, is susceptible to an Insecure Direct Object Reference (IDOR) vulnerability. The flaw exists due to inadequate validation of a user-controlled 'id' parameter during the registration process. This oversight allows unauthenticated attackers to supply an arbitrary user ID, enabling them to reset the password of any existing WordPress user, including those with administrative privileges. This exploit facilitates silent account takeover, as the system does not notify the victim of the credential change. Given the critical severity (CVSS 9.8) and the high impact of total administrative compromise on WordPress environments, immediate patching is required.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability leads to total account takeover of any WordPress user account. Attackers targeting administrative accounts gain full control over the WordPress installation, allowing for malicious plugin installation, sensitive data exfiltration, and secondary persistent access within the targeted environment.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the MemberDash plugin to a version beyond 1.8.5 immediately.\u003c/li\u003e\n\u003cli\u003eAudit WordPress user accounts and administrative logs for unauthorized password reset events or suspicious account registration patterns.\u003c/li\u003e\n\u003cli\u003eImplement strict rate limiting on registration endpoints to mitigate automated exploitation attempts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-06T03:35:40Z","date_published":"2026-09-06T03:35:40Z","id":"https://feed.craftedsignal.io/briefs/2026-09-memberdash-idor/","summary":"The MemberDash WordPress plugin contains an IDOR vulnerability allowing unauthenticated attackers to perform unauthorized password resets for arbitrary users via the registration registration process.","title":"CVE-2026-16310 Unauthenticated Password Reset in MemberDash","url":"https://feed.craftedsignal.io/briefs/2026-09-memberdash-idor/"}],"language":"en","title":"CraftedSignal Threat Feed - MemberDash (\u003c= 1.8.5)","version":"https://jsonfeed.org/version/1.1"}