WordPress Membership Plugin Flaw Lets Attackers Create Admin Accounts
A critical security vulnerability has been identified in the WordPress User Registration & Membership plugin, allowing unauthenticated attackers to create administrator accounts.
A critical security vulnerability has been identified in the WordPress User Registration & Membership plugin, allowing unauthenticated attackers to create administrator accounts.
The flaw, tracked as CVE-2026-1492, affects versions up to and including 5.1.2 of the plugin. This vulnerability carries a CVSS severity score of 9.8 out of 10 due to its potential impact and the lack of required authentication for exploitation.
The issue arises from improper privilege management within the plugin's registration form builder. The software fails to restrict the account roles new users can request, allowing attackers to intercept registration requests and inject an "administrator" role value.
The flaw, tracked as CVE-2026-1492, affects versions up to and including 5.1.2 of the plugin.
Consequently, attackers can gain full administrative access, enabling them to control the website, install backdoors, steal data, or redirect traffic. Security analysts have noted active exploitation attempts, with 74 attacks blocked in a 24-hour period.
To mitigate this threat, users must update to version 5.1.3, which addresses the vulnerability. Administrators should also audit user accounts for unauthorized administrator roles and rotate passwords to prevent unauthorized access.
Recent findings indicate other vulnerabilities, including a critical authentication bypass (CVE-2026-1779) and an authorization issue, highlighting the importance of maintaining a strict patch management schedule and utilizing a web application firewall.
Based on reporting by GBHackers.
