CVE-2026-1492Disclosure

HIGHCVSS 9.8 · CRITICAL

Exploitation observed; activity peaked at 11 mentions and remains active

Immediate actions

  • Patch affected systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to improper privilege management in all versions up to, and including, 5.1.2. This is due to the plugin accepting a user-supplied role during membership registration without properly enforcing a server-side allowlist. This makes it possible for unauthenticated attackers to create administrator accounts by supplying a role value during membership registration.

7.8/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Active exploitation appears in 13 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 47 mentions across 14 observed days

What's happening

  • Active exploitation reported across 13 signals
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 4 signals
  • Patch or workaround mentioned in 15 signals
  • Technical details provided in 34 signals
  • Disclosure: 23 classified signals
  • General: 8 classified signals
  • Peaked 10d ago at 11 mentions (2026-03-06); latest day: 2
  • 47 total mentions across 14 days

Deep dive

Activity timeline47 mentions / 14d
036811Mentions · 2026-03-03: 7Mentions · 2026-03-04: 1Mentions · 2026-03-05: 3Mentions · 2026-03-06: 11Mentions · 2026-03-07: 4Mentions · 2026-03-08: 1Mentions · 2026-03-10: 4Mentions · 2026-03-12: 1Mentions · 2026-03-13: 2Mentions · 2026-03-23: 1Mentions · 2026-04-11: 1Mentions · 2026-04-13: 5Mentions · 2026-04-14: 4Mentions · 2026-04-20: 2PoC Mentioned / Linked · 2026-03-06: 1PoC Mentioned / Linked · 2026-03-23: 1PoC Mentioned / Linked · 2026-04-13: 1PoC Mentioned / Linked · 2026-04-14: 1Exploit Tool / Code · 2026-03-23: 1Active Exploitation · 2026-03-05: 1Active Exploitation · 2026-03-06: 5Active Exploitation · 2026-03-07: 1Active Exploitation · 2026-03-08: 1Active Exploitation · 2026-03-10: 1Active Exploitation · 2026-03-13: 1Active Exploitation · 2026-04-11: 1Active Exploitation · 2026-04-13: 1Active Exploitation · 2026-04-14: 1Patch / Workaround · 2026-03-03: 1Patch / Workaround · 2026-03-05: 2Patch / Workaround · 2026-03-06: 3Patch / Workaround · 2026-03-07: 1Patch / Workaround · 2026-03-08: 1Patch / Workaround · 2026-04-13: 3Patch / Workaround · 2026-04-14: 3Patch / Workaround · 2026-04-20: 1Technical Details · 2026-03-03: 3Technical Details · 2026-03-04: 1Technical Details · 2026-03-05: 3Technical Details · 2026-03-06: 8Technical Details · 2026-03-07: 2Technical Details · 2026-03-08: 1Technical Details · 2026-03-10: 2Technical Details · 2026-03-12: 1Technical Details · 2026-03-13: 1Technical Details · 2026-03-23: 1Technical Details · 2026-04-13: 5Technical Details · 2026-04-14: 4Technical Details · 2026-04-20: 203-0303-0403-0503-0603-0703-0803-1003-1203-1303-2304-1104-1304-1404-20
Signal classification4 categories
Disclosure
2348.9%
Active Exploitation
919.1%
General
817.0%
Patch
714.9%
Referenced assets38 URLs
By indicator
Classification over time
DateTotalLabels
2026-03-037
Disclosure2General4Patch1
2026-03-041
Disclosure1
2026-03-053
Active Exploitation1Disclosure1Patch1
2026-03-0611
Active Exploitation5Disclosure5General1
2026-03-074
Active Exploitation1Disclosure2General1
2026-03-081
Disclosure1
2026-03-104
Active Exploitation1Disclosure2General1
2026-03-121
Disclosure1
2026-03-132
Disclosure1General1
2026-03-231
Disclosure1
2026-04-111
Active Exploitation1
2026-04-135
Disclosure2Patch3
2026-04-144
Disclosure3Patch1
2026-04-202
Disclosure1Patch1
Full discourse20 posts
  • IT-Connect.fr@ITConnect_fr
    Disclosure

    🛑 WordPress – CVE-2026-1492 : une faille dans un plugin permet de devenir admin très facilement 👇 Tous les détails - https://www.it-connect.fr/wordpress-cve-2026-1492-une-faille-dans-un-plugin-permet-de-devenir-admin-tres-facilement/ #WordPress #Web #infosec #cybersecurity https://t.co/sZKZcPM08K

    Post summary

    The tweet announces CVE-2026-1492, a WordPress plugin vulnerability that can grant admin access easily, and points to a link for more details.

    2911351.6K
    11.0K followersView on X
  • Gray Hats@the_yellow_fall
    Disclosure

    A critical 9.8 CVSS flaw (CVE-2026-1492) in the WordPress User Registration & Membership plugin lets unauthenticated attackers create admin accounts #WordPressSecurity #CyberSecurity #Vulnerability #InfoSec #PatchAlert #WebSecurity #WordPress #ThreatIntel https://securityonline.info/wordpress-security-alert-critical-privilege-escalation-flaw-in-popular-membership-plugin/

    Post summary

    A critical CVE-2026-1492 flaw in a WordPress plugin allows unauthenticated users to create admin accounts, but the post provides no PoC, exploit code, or patch information.

    02051423
    10.5K followersView on X
  • Vivek | ThreatIntel@VivekIntel
    Active Exploitation

    Active exploitation: Critical WordPress plugin vulnerability A flaw (CVE-2026-1492, CVSS 9.8) in the User Registration and Membership plugin is allowing attackers to create administrator accounts without authentication. The plugin is installed on 60,000+ WordPress sites, putting a large number of websites at risk.

    Post summary

    The post reports that CVE‑2026‑1492 is being actively exploited to create attacker‑controlled administrator accounts on over 60,000 WordPress sites. No patch, PoC, or exploit tool details are provided.

    6000081
    218 followersView on X
  • Jamaica Cyber Incident Response Team (JaCIRT)@cirtgovjm
    Disclosure

    🚨 Security Alert: Critical WordPress Vulnerability A critical vulnerability has been discovered in the WordPress User Registration & Membership plugin by WPEverest (CVE-2026-1492). Click the link below for more information 👇 https://cirt.gov.jm/alert/critical-vulnerability-wordpress-user-registration-membership-plugin-exploited-create https://t.co/U2bArP1Rmj

    Post summary

    A security alert announced a newly discovered critical vulnerability (CVE-2026-1492) in the WordPress User Registration & Membership plugin, with a link for additional details.

    01021167
    1.1K followersView on X
  • Enzamamul Haque@enzamamulhaqueo
    Patch

    CVE-2026-1492 — WordPress auth bypass. No login needed. Attacker hits admin-ajax.php, gets full admin access. Fix: Update User Registration & Membership to v5.1.3 now. Then check for unknown admin accounts. #MalwareRemoval #WordPressSecurity #CVE #WordPress https://t.co/TohHgZKFJN

    Post summary

    The tweet discloses CVE‑2026‑1492 as an authentication bypass that allows an attacker to gain full admin access via admin‑ajax.php, and it recommends updating the User Registration & Membership plugin to v5.1.3 to remediate the flaw.

    1002040
    7 followersView on X
  • dbugs@ptdbugs
    Disclosure

    User Registration & Membership WordPress plugin <= 5.1.2 - Unauthenticated Privilege Escalation via Membership Registration CVE: CVE-2026-1492 PT-Identifier: PT-2026-22718 Vendor: wpeverest Product: User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder CVSS: 9.8 Credits: Friderika Baranyai Description: The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to improper privilege management in all versions up to, and including, 5.1.2. This is due to the plugin accepting a user-supplied role during membership registration without properly enforcing a server-side allowlist. This makes it possible for unauthenticated attackers to create administrator accounts by supplying a role value during membership registration. References: • https://dbugs.ptsecurity.com/vulnerability/CVE-2026-1492 • https://www.wordfence.com/threat-intel/vulnerabilities/id/7e9fec92-f471-4ce9-9138-1c58ad658da2?source=cve • https://plugins.trac.wordpress.org/changeset/3469042/user-registration Exploit: https://github.com/the8frust/CVE-2026-1492 #dbugs_vuln

    Post summary

    A newly reported WordPress plugin flaw (CVE-2026-1492) enables unauthenticated users to create administrator accounts via role injection; the vulnerability is documented with a CVSS of 9.8 and a publicly available GitHub PoC.

    01011176
    733 followersView on X
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-1492 - critical 🚨 WordPress User Registration &amp; Membership &lt;= 5.1.2 - Unauthenticated Privilege Escalation &gt; User Registration &amp; Membership WordPress plugin &lt;= 5.1.2 contains an improper privile... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-1492 @pdnuc...

    Post summary

    A new critical CVE-2026-1492 affecting the WordPress User Registration & Membership plugin (<=5.1.2) is announced, detailing an unauthenticated privilege escalation flaw, but no proof‑of‑concept, patch information or active exploitation evidence is provided.

    00012141
    902 followersView on X
  • maru@maru1151157
    Disclosure

    🚨 CVE-2026-1492 (CVSS: 9.8) WordPressのUser Registration &amp; Membershipプラグイン(バージョン5.1.2まで)が不適切な権限管理の脆弱性。未認証攻撃者が管理者アカウントを生成可能。 https://maruomosquit.com/vulnerability/CVE-2026-1492/ #脆弱性 #セキュリティ

    Post summary

    The post announces CVE‑2026‑1492, a high‑severity privilege‑management flaw in a WordPress plugin that lets unauthenticated users create admin accounts, but no PoC, exploit, or patch is mentioned.

    00030129
    1.4K followersView on X
  • White Rabbitx 🏴‍☠️@TheRabbitPy
    Patch

    CVE‑2026‑1492 – WordPress User Registration & Membership auth bypass (Critical, CVSS 9.8): The plugin accepts a user‑supplied role during membership signup with no server‑side allowlist, so unauthenticated attackers can register directly as administrators and fully take over vulnerable sites. Update off ≤5.1.2 immediately and audit for rogue admin accounts. https://app.opencve.io/cve/CVE-2026-1492

    Post summary

    CVE‑2026‑1492 permits unauthenticated users to create admin accounts; the recommendation is to update to version ≤5.1.2 and audit for rogue users.

    1001025
    1.0K followersView on X
  • Emerson Yougbaré@emzrsxn
    Disclosure

    Un visiteur anonyme peut devenir administrateur de votre site WordPress. Aucun mot de passe à deviner, aucune faille technique complexe à exploiter. Juste une requête d'inscription légèrement modifiée. C'est ce que permet CVE-2026-1492, une vulnérabilité critique découverte dans le plugin User Registration & Membership, installé sur plus de 60 000 sites. Le problème est simple dans son principe : lors de la création d'un compte, le plugin ne vérifie pas correctement les paramètres envoyés par l'utilisateur. En manipulant cette requête, un attaquant peut s'attribuer directement un rôle administrateur sur le site cible. Sans interaction de l'administrateur légitime, sans alerte, sans trace visible. Une fois accès obtenu, les options sont larges : modifier ou supprimer le contenu publié, installer des extensions malveillantes, créer des portes dérobées, extraire la base de données des utilisateurs et de leurs informations de paiement, ou encore évincer les administrateurs existants. Les chercheurs de Wordfence ont déjà bloqué près de 300 tentatives d'exploitation en 48 heures. La faille est donc activement ciblée. Elle affecte toutes les versions du plugin jusqu'à la 5.1.2. Le correctif est disponible dans la version 5.1.3, la 5.1.4 étant la plus récente. La version payante Pro ne semble pas concernée. Une seconde vulnérabilité a été corrigée dans le même temps, cette fois dans le plugin All-in-One Microsoft 365 & Entra ID / Azure AD SSO Login (CVE-2026-2628). Elle permet à un attaquant non authentifié de contourner la procédure de connexion et d'accéder au site en se faisant passer pour n'importe quel utilisateur, y compris les administrateurs. Ce plugin est déployé sur plus de 600 sites. Pour les PME qui s'appuient sur WordPress pour leur site vitrine, leur boutique en ligne ou leur portail client : vérifiez vos plugins actifs, mettez à jour immédiatement vers les versions corrigées, et profitez-en pour passer en revue l'ensemble des extensions installées. Un plugin inutilisé et non mis à jour est une surface d'attaque qui coûte rien à éliminer. Source : Wordfence - lien en commentaire. #Cybersécurité #WordPress #Vulnérabilité #GestionDesRisques #PME #GRC #VeilleInformationnelle

    Post summary

    The post announces CVE‑2026‑1492, a critical privilege‑escalation flaw in the User Registration & Membership plugin, details how it can be abused via a modified sign‑up request, reports active exploitation, and references the patch available in versions 5.1.3 and 5.1.4.

    2000056
    1.6K followersView on X
  • Zyberwalls@ZyberWallS
    General

    New Vulnerability Analysis: CVE-2026-1492 Full analysis: https://www.zyberwalls.com/2026/03/cve-2026-1492-wordpress-admin-account-takeover-analysis.html

    Post summary

    The text merely announces a vulnerability analysis for CVE-2026-1492 and points to a webpage, lacking any concrete evidence of PoC, exploitation, patches, or technical details.

    0101046
    9 followersView on X
  • CCB Alert@CCBalert
    Active Exploitation

    Warning: Critical Improper Privilege Management in #WordPress plugin for User Registration &amp; Membership. CVE-2026-1492 CVSS: 9.8. Remote attackers can create admin accounts without authentication. Active exploitation is in progress. #Patch #Patch #Patch

    Post summary

    CVE-2026-1492, a high‑severity privilege‑management flaw in a WordPress plugin, is currently being actively exploited to create admin accounts, but no exploit code or patch details are supplied.

    02000242
    7.2K followersView on X
  • Zyberwalls@ZyberWallS
    Disclosure

    Attack chain behind CVE-2026-1492 👇 A WordPress membership plugin fails to validate the role parameter, allowing attackers to register as Administrator. Result → Complete site compromise. Full analysis: https://www.zyberwalls.com/2026/03/cve-2026-1492-wordpress-admin-account-takeover-analysis.html #CyberSecurityNews #WordPressSecurity #CVE2026

    Post summary

    The tweet discloses a WordPress plugin flaw that allows attackers to register as administrators via a role parameter bypass, potentially leading to full site compromise.

    0002048
    9 followersView on X
  • Zyberwalls@ZyberWallS
    Disclosure

    New Research: CVE-2026-1492 A critical WordPress plugin flaw lets attackers create administrator accounts without authentication — leading to full website takeover. Breakdown, exploit flow &amp; defense ⬇️ https://www.zyberwalls.com/2026/03/cve-2026-1492-wordpress-admin-account-takeover-analysis.html #CyberSecurity #WordPress #CVE #Vulnerability https://t.co/LBHtoQWNfm

    Post summary

    A new research post highlights CVE-2026-1492, a critical WordPress plugin flaw that allows unauthenticated creation of admin accounts, enabling full site takeover, but provides no PoC, exploit code, active usage reports, or patch guidance.

    0101057
    9 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-1492 Privilege Escalation in WordPress User Registration &amp; Membership Plugin 5.1.2 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-1492

    Post summary

    The snippet announces a privilege escalation vulnerability in WordPress User Registration & Membership Plugin 5.1.2 but offers no further technical or actionable details.

    1001088
    4.0K followersView on X
  • iototsecnews@iototsecnews
    Disclosure

    WordPress Membership プラグインの脆弱性 CVE-2026-1492 が FIX:認証回避と管理者権限窃取 https://iototsecnews.jp/2026/04/13/critical-wordpress-plugin-flaw-lets-attackers-bypass-authentication-and-gain-admin-access/ この脆弱性 CVE-2026-1492 の原因は、ユーザーが入力した情報のチェックが不十分だったことや、本来は管理者しか実行できない処理を、誰でも動かせる状態になっていた点にあります。Web サイトの表側で使われるセキュリティ用の合言葉が、誰もが見える場所に置かれていたことも、問題を広げる一因となりました。これにより、攻撃者は正しい手続きを踏まずに裏口から入り込めるようになっていました。ご利用のチームは、ご注意ください。 #CVE20261492 #Membership #Vulnerability #WordPress

    Post summary

    The article announces the CVE-2026-1492 vulnerability in the WordPress Membership plugin, explaining how lack of input validation and exposed admin controls allow authentication bypass and privilege escalation, but it does not provide any PoC, exploit code, or patch details.

    01000146
    486 followersView on X
  • UNDERCODE TESTING@UndercodeUpdate
    Patch

    🚨 #CVE-2026-1492: Unauthenticated Admin Takeover in 200k+ WordPress Sites – Patch NOW! + Video https://undercodetesting.com/cve-2026-1492-unauthenticated-admin-takeover-in-200k-wordpress-sites-patch-now-video/ Educational Purposes!

    Post summary

    The tweet alerts to CVE‑2026‑1492, encourages patching for over 200k WordPress sites, provides a PoC video via link, but does not detail exploit code or active exploitation.

    0001039
    492 followersView on X
  • ThreatCluster@threatcluster
    Disclosure

    BREAKING: New CVE-2026-1492 flaw in WordPress User Registration &amp; Membership plugin up to v5.1.2 allows remote auth bypass and full admin takeover on thousands of sites. https://threatcluster.io/cluster/critical-cve-2026-1492-vulnerability-in-wordpress-plugin-all-f9a7f9c4

    Post summary

    A new CVE-2026-1492 flaw in a WordPress plugin permits remote authentication bypass and full admin takeover, potentially affecting thousands of sites. The post announces the vulnerability but does not provide PoC or exploit details or patches.

    0100065
    149 followersView on X
  • Cyber Edition@CyberEdition
    Patch

    🔥 CYFIRMA flags CVE-2026-1492 in User Registration &amp; Membership plugin. Attackers can bypass login and gain admin access via crafted requests. No creds needed. Patch to v5.1.3 now. Source:https://www.cyfirma.com/research/cve-2026-1492-wordpress-user-registration-membership-authentication-bypass-flaw/ #WordPress #CyberSecurity

    Post summary

    CYFIRMA reports an authentication bypass in User Registration & Membership WP plugin, noting that a patch to v5.1.3 is now available.

    00010103
    716 followersView on X
  • CTIWatch@ctiwatchcloud
    Active Exploitation

    🚨 [CRITICAL] Active exploitation detected: CVE-2026-1492 Exploit in the wild confirmed for CVE-2026-1492 (CVSS 9.8). The User Registration &amp; Membership – Custom Registration Form Builder, Custom Login Form, ... 🔗 http://ctiwatch.cloud/alerts #ZeroDay #ExploitInWild #CyberSecurity

    Post summary

    The post declares that CVE-2026-1492 is being actively exploited in the wild with a CVSS score of 9.8, yet it offers no proof of concept, exploit code, or patch information.

    00010260
    5.6K followersView on X

Explore more