logo

WordPress membership plugin bug exploited to create admin accounts

ID: 8ac745a3-5b88-519e-895b-23ddec558803

STIX ID: report--8ac745a3-5b88-519e-895b-23ddec558803

Feed Name: Bleeping Computer

Threat Score
75/100

Date Published: 2026-03-05

Date Updated: 2026-04-20

Author: Bill Toulas

...
...

A critical vulnerability (CVE-2026-1492, CVSS 9.8) in the User Registration & Membership WordPress plugin (installed on >60,000 sites) allows unauthenticated attackers to specify roles and create administrator accounts; Wordfence reported blocking more than 200 exploitation attempts in 24 hours and site owners are advised to update to 5.1.3/5.1.4 or disable the plugin to mitigate full site compromise.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.