WordPress Plugin Vulnerability Enables Admin Takeover via Auth Bypass
ID: 8bef6a94-50ac-5a01-a3ef-1587c9e8a7b8
STIX ID: report--8bef6a94-50ac-5a01-a3ef-1587c9e8a7b8
Feed Name: GBHackers
Threat Score
This advisory details CVE-2026-1492, a critical (CVSS 9.8) authentication bypass and privilege escalation in the User Registration & Membership WordPress plugin (≤5.1.2) where unauthenticated attackers can abuse AJAX-based registration endpoints and exposed client-side parameters to gain full administrative control; public exploit scripts exist and a patch (5.1.3) is available.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
