Vivek | ThreatIntel[verified]@VivekIntelActive Exploitation
The post reports that CVE‑2026‑1492 is being actively exploited to create attacker‑controlled administrator accounts on over 60,000 WordPress sites. No patch, PoC, or exploit tool details are provided.
dbugs[verified]@ptdbugsDisclosure
A newly reported WordPress plugin flaw (CVE-2026-1492) enables unauthenticated users to create administrator accounts via role injection; the vulnerability is documented with a CVSS of 9.8 and a publicly available GitHub PoC.
maru[verified]@maru1151157Disclosure
The post announces CVE‑2026‑1492, a high‑severity privilege‑management flaw in a WordPress plugin that lets unauthenticated users create admin accounts, but no PoC, exploit, or patch is mentioned.
White Rabbitx 🏴☠️[verified]@TheRabbitPyPatch
CVE‑2026‑1492 permits unauthenticated users to create admin accounts; the recommendation is to update to version ≤5.1.2 and audit for rogue users.
Emerson Yougbaré[verified]@emzrsxnDisclosure
The post announces CVE‑2026‑1492, a critical privilege‑escalation flaw in the User Registration & Membership plugin, details how it can be abused via a modified sign‑up request, reports active exploitation, and references the patch available in versions 5.1.3 and 5.1.4.
ThreatCluster[verified]@threatclusterDisclosure
A new CVE-2026-1492 flaw in a WordPress plugin permits remote authentication bypass and full admin takeover, potentially affecting thousands of sites. The post announces the vulnerability but does not provide PoC or exploit details or patches.
IT-Connect.fr@ITConnect_frDisclosure
The tweet announces CVE-2026-1492, a WordPress plugin vulnerability that can grant admin access easily, and points to a link for more details.
Gray Hats@the_yellow_fallDisclosure
A critical CVE-2026-1492 flaw in a WordPress plugin allows unauthenticated users to create admin accounts, but the post provides no PoC, exploit code, or patch information.