Sceawere
Vulnerability Detail
CVE-2026-94235UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
MemberHero Arbitrary Email Relay Vulnerability
Vulnerability Metadata
- Severity
- Medium
- Score / CVSS
- 4.3
- Creation Date
- 8h ago
- Vendor
- Unknown
- Product
- MemberHero
- Attack Type
- CWE-862 Missing Authorization
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
- Attack Complexity
- LOW
Narrative and Response
Description
The MemberHero WordPress plugin through 6.9 does not perform any capability or nonce check on one of its AJAX actions, allowing any authenticated user, such as a subscriber, to make the site send arbitrary HTML emails to arbitrary recipients from its own mail system, which can be abused to relay phishing carrying the site's identity and domain reputation.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "4.3",
"pubDate": "2026-10-11T07:17:29.420Z",
"pubdate": "2026-10-11T07:17:29.420Z",
"executiveSummary": "The MemberHero WordPress plugin, in versions up to 6.9, contains a critical security flaw involving an unauthenticated AJAX action. The vulnerability stems from a lack of capability verification and nonce validation, allowing any authenticated user—including low-privileged roles such as subscribers—to perform unauthorized actions.\nSpecifically, the plugin permits the remote execution of an arbitrary email sending function. An attacker can leverage this to transmit forged emails to any recipient, utilizing the hosting site's internal mail server and domain reputation. This vector effectively turns the vulnerable WordPress installation into an open relay for phishing campaigns.\nThe impact is significant, as attackers can bypass standard security controls to send emails that appear legitimate because they originate from the organization's verified domain. This behavior poses substantial risks to brand integrity, domain deliverability, and user trust. Because the vulnerability requires only a basic subscriber-level account, the barrier to entry for exploitation is low. Organizations utilizing MemberHero 6.9 or earlier are advised to restrict access to these functions or update the plugin immediately upon the release of a security patch.",
"technicalDetails": "The root cause of this vulnerability is the absence of access control and cross-site request forgery (CSRF) protection within an AJAX handler implemented in the MemberHero plugin. In the WordPress architecture, AJAX actions intended for specific user roles must include checks for current_user_can() to verify capabilities and check_ajax_referer() to validate nonces.\nThe vulnerable code component fails to implement these defensive checks, exposing a server-side method that accepts arbitrary parameters to construct and dispatch emails. Because the function is registered as an AJAX action, it is accessible via the WordPress admin-ajax.php endpoint. By sending a crafted POST request to this endpoint, an attacker can manipulate the parameters typically used by the plugin's legitimate mailing functionality.\nThe attack flow follows a predictable sequence: First, the attacker authenticates as a standard subscriber, which is a default role on many WordPress installations. Second, the attacker crafts a malicious HTTP POST request targeting the admin-ajax.php file, identifying the specific action name associated with the email dispatching function. Third, the request payload includes the 'to' address, the 'subject' line, and the 'body' content, which may contain malicious HTML, links, or phishing lures. Finally, the server processes the request without validating the user's authority, utilizing the underlying wp_mail() function to send the email.\nSince the email originates from the WordPress site's mail server, it will likely pass through SPF, DKIM, and DMARC checks, increasing the success rate of phishing attempts. The impact is not limited to mere spam distribution; it facilitates advanced social engineering by leveraging the site's established domain reputation. The post-exploitation impact includes potential blacklisting of the domain by email service providers, loss of user trust, and potential legal or compliance repercussions resulting from the abuse of the site’s mail infrastructure."
}