Skip to content
firewallpulse
Bits, bytes and breaking security news
Vulnerabilities

Tonda Membership Plugin Critical Auth Bypass Lets Attackers Gain Admin Access Without Credentials

Select-Themes plugin allows attackers to gain administrative access without credentials, rated 9.8 CVSS.

Tonda Membership Plugin Critical Auth Bypass Lets Attackers Gain Admin Access Without Credentials
Illustration: Firewall Pulse

Key points

  • CVE-2026-62022 affects Tonda Membership versions up to 1.0.1.
  • The vulnerability is rated 9.8 Critical by the NVD.
  • Attackers can escalate privileges without authenticating.

The Select-Themes Tonda Membership plugin contains a severe unauthenticated privilege escalation vulnerability, tracked as CVE-2026-62022. This flaw allows remote attackers to bypass standard authentication controls and gain elevated access rights. The issue impacts all versions of the plugin up to and including 1.0.1.

Root cause

The National Vulnerability Database categorises this weakness under CWE-266, indicating improper privilege management. The core technical failure lies in the plugin’s handling of user permissions. Specifically, the code fails to verify the identity or role of the user initiating certain administrative actions. This absence of proper access control checks allows external actors to manipulate the application’s internal state.

Attack path

An attacker does not need valid login credentials to exploit this issue. By sending crafted requests to the affected WordPress site, they can trigger the privilege escalation logic. The exploit path is direct, requiring no prior session or cookie validation. Once the unauthenticated request is processed, the system grants the attacker higher-level permissions. This effectively transforms a public-facing component into an administrative entry point.

Affected versions

The vulnerability is present in the following releases of the Tonda Membership plugin developed by Select-Themes:

  • Version 1.0.1
  • Version 1.0.0
  • All prior versions

Sites running version 1.0.2 or later are not affected by this specific CVE record. Users should verify their installed version immediately to determine exposure.

Mitigation

  • Review installed plugin versions against the affected list above.
  • Monitor server logs for suspicious privilege changes or admin activity.
  • Restrict access to the WordPress dashboard using IP whitelisting.
  • Ensure the site is not publicly accessible if the plugin is not in use.

What to do and how to stay safe: Tonda Membership

  • Audit your WordPress installation for the Tonda Membership plugin and check its version number.
  • Inspect access logs for unauthenticated requests attempting to modify user roles or permissions.
  • Limit administrative access to trusted network ranges to reduce the attack surface.
  • Wait for the vendor to release a patched version before re-enabling public access.

Step-by-step guide: Out-of-band patches: what small businesses need to know

General security guidance from the Firewall Pulse newsroom. It is not confirmed advice from the organisations named in this story.

Frequently asked questions

Which CVE ID tracks this Tonda Membership vulnerability?

The issue is tracked as CVE-2026-62022.

What is the CVSS score for this flaw?

The National Vulnerability Database rates the severity as 9.8 Critical.

Do attackers need a login to exploit this?

No, the vulnerability allows unauthenticated privilege escalation, meaning no credentials are required.

Sources

  1. CVE Program
Tonda MembershipSelect-ThemesCVE-2026-62022WordPressPrivilege Escalation

Related stories