CVE-2026-1492
CVSS 9.8 CRITICAL: the User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content… EPSS 28% (98º percentile).
Vulnerabilità ed exploit · Attacco ad app web
Questo permette a un attaccante di ottenere un account admin senza autenticazione.
1 fonte · 5 mar
CVSS 9.8 CRITICAL: the User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content… EPSS 28% (98º percentile).
BleepingComputer
WordPress membership plugin bug exploited to create admin accounts
Hackers are exploiting a critical vulnerability in the User Registration & Membership plugin, which is installed on more than 60,000 WordPress sites.
originalePart of the PlainSec briefing for 2026-03-06
Every edition of this story: Vulnerabilità Plugin Consente Creazione di Account Admin WordPress