WordPress Membership Plugin Vulnerability Let Attackers Create Admin Accounts
A critical security vulnerability, identified as CVE-2026-1492, has been discovered in the User Registration & Membership plugin for WordPress .
A critical security vulnerability, identified as CVE-2026-1492, has been discovered in the User Registration & Membership plugin for WordPress .
This vulnerability permits unauthenticated attackers to bypass security controls and create administrator accounts, potentially leading to a complete website takeover.
The User Registration & Membership plugin enables website owners to create custom registration forms and manage user profiles. However, versions up to and including 5.1.2 have a severe improper privilege management issue. The plugin allows new users to register with a user-supplied role without enforcing a server-side allowlist.
Due to the lack of verification for the requested role, attackers can register as administrators, gaining full control over the affected WordPress site without needing prior authentication.
Once inside, attackers can steal sensitive user data, modify website content, or install malicious backdoors. This vulnerability carries a critical severity CVSS score of 9.8.
A critical security vulnerability, identified as CVE-2026-1492, has been discovered in the User Registration & Membership plugin for WordPress .
Security systems have detected active exploitation attempts, blocking 74 attacks over the past 24 hours. Additionally, version 5.1.2 is vulnerable to an Authentication Bypass, tracked as CVE-2026-1779, allowing attackers to bypass login mechanisms entirely.
Website administrators should take immediate action to secure their platforms. The software vendor has released a patch that restricts which roles can be assigned during registration. This update effectively blocks users from submitting elevated roles and stops the privilege escalation attack.
According to Wordfence , the vulnerability was disclosed on March 2, 2026, and updated on March 3. Users should immediately update the plugin to version 5.1.3 or later. Additionally, administrators should conduct an access review to audit existing user accounts for any unauthorized administrator profiles.
Implementing traffic monitoring on registration endpoints to watch for suspicious activity or abnormal role requests is also recommended. As this flaw does not require an attacker to log in first, websites running older, vulnerable versions remain highly exposed to the creation of administrator accounts.
Applying the latest security update is the most effective measure to secure membership registration forms and protect the website from unauthorized access .
Based on reporting by Cyber Security News.
