logo

WordPress Plugin Vulnerability Enables Admin Takeover via Auth Bypass

ID: 8bef6a94-50ac-5a01-a3ef-1587c9e8a7b8

STIX ID: report--8bef6a94-50ac-5a01-a3ef-1587c9e8a7b8

Feed Name: GBHackers

Threat Score
90/100

Date Published: 2026-04-13

Date Updated: 2026-07-21

Author: Mayura Kathir

...
...

This advisory details CVE-2026-1492, a critical (CVSS 9.8) authentication bypass and privilege escalation in the User Registration & Membership WordPress plugin (≤5.1.2) where unauthenticated attackers can abuse AJAX-based registration endpoints and exposed client-side parameters to gain full administrative control; public exploit scripts exist and a patch (5.1.3) is available.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.