Track vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-16310: MemberDash plugin lets anyone change any user’s password

CVE-2026-16310 · published 1 month ago
Summary

The MemberDash add‑on for WordPress does not check the user ID supplied during registration. Because of this, anyone on the internet can reset the password of any site user—including administrators—and take over the account without the user knowing. Update the plugin to a newer version or remove it if you cannot upgrade, and consider forcing password resets for all accounts.

What to do

The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.

Affected software
VendorProductAffected versions
learndash memberdash <= 1.8.5
Original advisory text
MemberDash <= 1.8.5 - Unauthenticated Account Takeover via Insecure Direct Object Reference via 'id' Parameter
The MemberDash plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.8.5 via the 'id' parameter due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to change the password of any WordPress user, including administrators, by supplying an arbitrary user ID during registration, and take over their account without any notification sent to the victim.
Fix within
Internet-facing 3 days
Internal 60 days
  • Not known to be exploited
  • Can be exploited automatically
  • Gives an attacker full control
Severity
9.8 Critical
Exploitation
<1% chance of attack within 30 days
Type
CWE-639Authorization Bypass Through User-Controlled Key
Timeline
Published6 Sep 2026
Updated7 Oct 2026
First seen6 Sep 2026
Sources
CVE-2026-16310 · MITRE
Track software like this
Free during beta