By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: WordPress membership plugin bug exploited to create admin accounts
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > WordPress membership plugin bug exploited to create admin accounts
Tech News

WordPress membership plugin bug exploited to create admin accounts

By admin 3 Min Read
Share
SHARE

Hackers are exploiting a critical vulnerability in the User Registration & Membership plugin, which is installed on more than 60,000 WordPress sites.

Developed by WPEverest, the plugin provides membership and user registration management features, including custom forms, payment integrations with PayPal and Stripe, bank transfers, and analytics.

The security vulnerability is tracked as CVE-2026-1492 and received a critical severity rating of 9.8. Because the plugin accepts a user-supplied role during membership registration, hackers can create administrator accounts without authentication.

An administrator account has full access on the website, and it is required to install plugins and themes, edit PHP code, change security settings, modify site content, and lock out legitimate owners or admins.

An attacker with this level of access can steal data, such as the database of registered users, and embed malicious code to distribute malware to visitors.

Researchers at WordPress security company Defiant, the maker of the Wordfence security plugin, blocked more than 200 attempts to exploit CVE-2026-1492 in customer environments in the past 24 hours.

The vulnerability affects all versions of User Registration & Membership through 5.1.2. The developer released a fix in version 5.1.3 of the plugin. Website admins are advised to update to the latest version of the plugin, which is currently 5.1.4, released last week.

If updating is not possible, the recommendation is to temporarily disable or uninstall the plugin.

According to Wordfence data, CVE-2026-1492 is the most severe vulnerability in the User Registration & Membership plugin disclosed this year.

Hackers are constantly targeting WordPress sites for malicious activities that include malware distribution, phishing, hosting command-and-control servers, proxy malicious traffic, or to store stolen data.

In January 2026, hackers began exploiting a maximum-severity flaw (CVE-2026-23550) in the Modular DS WordPress plugin, allowing them to bypass authentication remotely and access vulnerable sites with admin-level privileges.

tines

Malware is getting smarter. The Red Report 2026 reveals how new threats use math to detect sandboxes and hide in plain sight.

Download our analysis of 1.1 million malicious samples to uncover the top 10 techniques and see if your security stack is blinded.

You Might Also Like

Plans for new Irish supercomputer CASPIR moves to next stage

5 new WhatsApp Features you Should Start Using

10 Hidden iOS 26.4 Features You Should Be Using on Your iPhone

File read flaw in Smart Slider plugin impacts 500K WordPress sites

TeamPCP Hacks Checkmarx GitHub Actions Using Stolen CI Credentials

TAGGED: Actively Exploited, Admin, Administrator, Plugin, privilege escalation, Vulnerability, Website, WordPress
Share This Article
Facebook Twitter Copy Link
Previous Article Hyperliquid Policy Center Maps Out Multi-Year Agenda, CEO Sets 3 Key Goals
Next Article Here’s Every Country Directly Impacted by the War on Iran
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

Breathing danger: WHO identifies world’s most polluted countries and cleanest nations
World News
Plans for new Irish supercomputer CASPIR moves to next stage
Tech News
Oil prices and markets look for direction amid conflicting messages from Iran and the US
Business
MEPs urge Commission leaders to stop Russia from returning to the Venice Biennale
World News
Ripple CEO Says XRP Utility Is Company’s ‘North Star’, Acquisitions Overperforming
Crypto
How Old Was Carolyn Bessette When She Met JFK Jr.? Their Relationship
Celebrity
PS6 Could Still Cost $699 With “Reasonable Subsidy,” Bill of Materials Estimated at $760 – Rumor
Gaming News

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

Investing £5 a day could help me build a second income of £329 a month!

Brussels unveils plans for a European Degree but struggles to explain why

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
Plans for new Irish supercomputer CASPIR moves to next stage
March 29, 2026
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?