WordPress Membership Plugin Flaw Lets Attackers Create Admin Accounts
ID: 7d2962c3-39e3-5970-909f-aab43ec0b277
STIX ID: report--7d2962c3-39e3-5970-909f-aab43ec0b277
Feed Name: GBHackers
Threat Score
A critical unauthenticated privilege-escalation vulnerability (CVE-2026-1492, CVSS 9.8) in the WordPress User Registration & Membership plugin (≤5.1.2) allows attackers to register accounts with an administrator role; active exploitation attempts were observed and the vendor patched the issue in version 5.1.3 — site owners should update immediately and audit for unauthorized admin accounts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
