A critical zero-day vulnerability in the User Registration & Membership plugin for WordPress (CVE-2026-1492) is currently being exploited to create unauthorized administrator accounts.
The flaw allows unauthenticated attackers to gain complete control over affected websites by supplying a custom user role during the registration process.
Vulnerability Details
- Plugin: User Registration & Membership (developed by WPEverest)
- Affected Versions: All versions up to and including 5.1.2
- Severity: Critical (CVSS score of 9.8)
- The Exploit: The plugin fails to use a server-side allowlist for user roles during registration. Attackers can bypass standard restrictions to assign themselves the “administrator” role, granting them full access to install malicious plugins, steal user databases, and embed malware.
Recent Related Exploits (2026)
Several other WordPress plugins have faced similar administrator-level takeovers recently:
- Modular DS Connector (CVE-2026-23550): A CVSS 10.0 vulnerability exploited in January 2026 allowed attackers to bypass authentication entirely via a REST endpoint to gain admin access.
- s2Member (CVE-2026-1994): A privilege escalation bug in versions up to 260127 allowed unauthenticated attackers to take over administrator accounts by resetting passwords without proper identity validation.
- Advanced Custom Fields: Extended: A privilege escalation flaw affecting 100,000 sites was patched in late 2025/early 2026 (version 0.9.2.2).
Required Actions
- Update Immediately: Upgrade the User Registration & Membership plugin to version 5.1.3 or later.
- Audit Accounts: Review all site administrators and delete any unknown accounts, such as those with generic “admin” names or placeholder emails.
- Monitor Logs: Check for suspicious registration activity or unauthorized changes to site content and settings.