CVE-2026-1779Disclosure

LOWCVSS 8.1 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

The User Registration & Membership plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.1.2. This is due to incorrect authentication in the 'register_member' function. This makes it possible for unauthenticated attackers to log in a newly registered user on the site who has the 'urm_user_just_created' user meta set.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-288

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 4 signals
  • Disclosure: 4 classified signals
  • Peaked 1d ago at 3 mentions (2026-02-26); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-02-26: 3Mentions · 2026-03-03: 1Technical Details · 2026-02-26: 3Technical Details · 2026-03-03: 102-2603-03
Signal classification1 categories
Disclosure
4100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-02-263
Disclosure3
2026-03-031
Disclosure1
Full discourse4 posts
  • CRAC Learning - Tech@cracbot
    Disclosure

    CVE-2026-1779 (CVSS:8.1, HIGH) is Awaiting Analysis. The User Registration & Membership plugin for WordPress is vulnerable to authentication bypass in versions up to, and in..https://nvd.nist.gov/vuln/detail/CVE-2026-1779 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post announces CVE-2026-1779, a high‑severity authentication bypass in the User Registration & Membership WordPress plugin, with no PoC, exploit, or patch details provided.

    1000027
    173 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-1779 The User Registration & Membership plugin for WordPress is vulnerable to authentication bypass in versions up to, and including, 5.1.2. This is due to incorrect authent… https://www.cve.org/CVERecord?id=CVE-2026-1779

    Post summary

    The User Registration & Membership plugin for WordPress is vulnerable to authentication bypass (CVE-2026-1779) in versions up to 5.1.2, with no mention of patches or exploitation.

    0000095
    56.6K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-1779 Authentication Bypass in WordPress User Registration & Membership Plugin 5.1.2 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-1779

    Post summary

    A new authentication bypass vulnerability (CVE-2026-1779) has been identified in WordPress User Registration & Membership Plugin 5.1.2, with details available on Vulmon.

    0000034
    4.0K followersView on X
  • CVETodo@CveTodo
    Disclosure

    **CVE-2026-1779** pertains to a security flaw in the **User Registration & Membership** plugin for WordPress, specifically affecting versions **up to and including 5.1.2**. The vulnerability involves an **authentication bypass** due to flawed logic in the `register_member` function, which allows unauthenticated attackers to log in as newly registered users who have the `urm_user_just_created` user meta set. #Cybersecurity #CVE #HighSeverity #SecurityAlert #RemoteCodeExecution #AuthBypass https://cvetodo.com/cve/CVE-2026-1779

    Post summary

    The post announces CVE‑2026‑1779, an authentication bypass in the User Registration & Membership plugin for WordPress (v5.1.2 and earlier), allowing unauthenticated attackers to log in as newly registered users.

    0000043
    20 followersView on X

Explore more