logo

WordPress Membership Plugin Flaw Lets Attackers Create Admin Accounts

ID: 7d2962c3-39e3-5970-909f-aab43ec0b277

STIX ID: report--7d2962c3-39e3-5970-909f-aab43ec0b277

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-03-06

Date Updated: 2026-04-22

Author: Divya

...
...

A critical unauthenticated privilege-escalation vulnerability (CVE-2026-1492, CVSS 9.8) in the WordPress User Registration & Membership plugin (≤5.1.2) allows attackers to register accounts with an administrator role; active exploitation attempts were observed and the vendor patched the issue in version 5.1.3 — site owners should update immediately and audit for unauthorized admin accounts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.