CVE-2026-1492
CVSS 9.8 CRITICAL: the User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content… EPSS 28% (98th percentile).
Vulnerabilities & Exploits · Web App Attack
Attackers can set a role at signup to create administrator accounts without authentication. More than 60,000 sites use the plugin; Wordfence blocked 200+ attempts. CVE-2026-1492, severity 9.8.
1 source · Mar 5
CVSS 9.8 CRITICAL: the User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content… EPSS 28% (98th percentile).
BleepingComputer
WordPress membership plugin bug exploited to create admin accounts
Hackers are exploiting a critical vulnerability in the User Registration & Membership plugin, which is installed on more than 60,000 WordPress sites.
originalPart of the PlainSec briefing for 2026-03-06
Every edition of this story: Plugin Flaw Lets Attackers Create WordPress Admin Accounts