CVE-2026-1492
CVSS 9.8 CRITICAL: the User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content… EPSS 28% (98º percentile).
Vulnerabilità · 208 giorni fa
Critical flaw (CVE-2026-1492, severity 9.8) in WPEverest User Registration & Membership lets attackers supply a role during signup to create administrator accounts without authentication; >60,000 sites affected and Wordfence blocked 200+ exploit attempts. Update to 5.1.3+ (current 5.1.4) immediately or disable the plugin until patched.
CVSS 9.8 CRITICAL: the User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content… EPSS 28% (98º percentile).
1 fonte che coprono questa storia
WordPress membership plugin bug exploited to create admin accounts
Hackers are exploiting a critical vulnerability in the User Registration & Membership plugin, which is installed on more than 60,000 WordPress sites.
Part of the PlainSec briefing for 2026-03-15