THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-83628 (MEDIUM 4.3) — The Theme My Login plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 7.1.15 on Multisite installations. This is due to the `tml_ms_signup_handler()` function's `gimmeanotherblog` branch failing to enforce the network's `active_signup` r

[NVD] CVE-2026-83628 (MEDIUM 4.3) — The Theme My Login plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 7.1.15 on Multisite installations. This is due to the `tml_ms_signup_handler()` function's `gimmeanotherblog` branch failing to enforce the network's `active_signup` r

mednvdPublished 2026-09-05

CVE-2026-83628 CVSS: 4.3 MEDIUM Published: 2026-09-05T06:17:10.230

The Theme My Login plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 7.1.15 on Multisite installations. This is due to the `tml_ms_signup_handler()` function's `gimmeanotherblog` branch failing to enforce the network's `active_signup` registration policy, checking only `is_user_logged_in

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-83628