Critical flaw (CVE-2026-1492, severity 9.8) in WPEverest User Registration & Membership lets attackers supply a role during signup to create administrator accounts without authentication; >60,000 sites affected and Wordfence blocked 200+ exploit attempts. Update to 5.1.3+ (current 5.1.4) immediately or disable the plugin until patched.
Part of the PlainSec briefing for 2026-03-15