Vulnerabilities & Exploits · Web App Attack

Plugin Flaw Lets Attackers Create WordPress Admin Accounts

Attackers can set a role at signup to create administrator accounts without authentication. More than 60,000 sites use the plugin; Wordfence blocked 200+ attempts. CVE-2026-1492, severity 9.8.

1 source · Mar 5

CVE-2026-1492

NVD KEV

CVSS 9.8 CRITICAL: the User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content… EPSS 28% (98th percentile).

Timeline

Sources

Part of the PlainSec briefing for 2026-03-06

Every edition of this story: Plugin Flaw Lets Attackers Create WordPress Admin Accounts

More from today