Vulnerabilities · 194 days ago

Exploit Creates Admin Accounts in WPEverest Plugin (CVE-2026-1492)

Critical flaw (CVE-2026-1492, severity 9.8) in WPEverest User Registration & Membership lets attackers supply a role during signup to create administrator accounts without authentication; >60,000 sites affected and Wordfence blocked 200+ exploit attempts. Update to 5.1.3+ (current 5.1.4) immediately or disable the plugin until patched.

CVE-2026-1492

NVD KEV

CVSS 9.8 CRITICAL: the User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content… EPSS 28% (98th percentile).

Timeline

Sources

1 source covering this story

Entities

Part of the PlainSec briefing for 2026-03-15

Editions

Related stories