A newly discovered critical security flaw in the widely used WordPress User Registration & Membership plugin has exposed millions of websites to complete takeover attacks.
Officially tracked as CVE-2026-1492, the vulnerability allows unauthenticated attackers to create administrator accounts without any user interaction.
The flaw affects all plugin versions up to and including 5.1.2 and carries a CVSS severity score of 9.8/10, classifying it as critical.
Since the bug can be exploited remotely and requires no authentication, it poses a severe risk to any unpatched WordPress installation using this plugin.
Vulnerability Details and Impact
The issue stems from a privilege management flaw in the plugin’s custom registration form builder.
Discovered by security researcher Friderika Baranyai, known as Foxyyy from Wordfence Intelligence, the vulnerability occurs because the plugin fails to validate user roles during the registration process.
When a new user registers on a vulnerable WordPress site, the plugin accepts the user-supplied role value without verifying if it belongs to an allowed list on the server side.
This oversight enables attackers to intercept the registration request and inject an “administrator” role value into the payload.
Once the manipulated request is processed, WordPress automatically grants the attacker full administrative privileges, giving them unrestricted control over the entire site.
With admin-level access, threat actors can easily:
- Install malicious backdoors to maintain long-term access.
- Steal sensitive data from user databases.
- Inject malware or redirects to lead visitors to phishing or exploit-laden pages.
Wordfence analysts have already observed active exploitation attempts in the wild. According to their data, 74 distinct attack attempts targeting CVE-2026-1492 were detected and blocked within a single 24-hour window.
This high level of automation underscores how rapidly malicious actors scan and weaponize new WordPress vulnerabilities to compromise outdated sites.
The plugin’s developers have issued an urgent patch addressing the privilege escalation bug in version 5.1.3.
All website owners using version 5.1.2 or earlier are strongly urged to update immediately to version 5.1.3 or the latest available release.
Site administrators should also audit their user accounts for any unexpected or unauthorized administrator entries.
If found, these accounts must be deleted right away, and all passwords must be rotated to prevent lingering access from compromised sessions.
Additionally, enabling a Web Application Firewall (WAF) such as Wordfence or Cloudflare provides an added layer of defense against similar privilege escalation exploits.
A strict patch management routine remains vital given the continued targeting of WordPress ecosystem plugins by opportunistic attackers.
The User Registration & Membership plugin has faced multiple security challenges recently. In fact, weeks before this latest disclosure, researchers identified another critical authentication bypass vulnerability (CVE-2026-1779) and a missing authorization flaw that allowed arbitrary post-deletion.
These recurring issues highlight the growing need for continuous monitoring, timely patching, and strong access control policies across all WordPress deployments.
As attackers increasingly automate their exploitation of plugin flaws, rapid response and vigilant security hygiene are the only defenses standing between a safe website and a full-scale compromise.
Follow us on Google News , LinkedIn and X to Get More Instant Updates. Set Cyberpress as a Preferred Source in Google.