Skip to main content
Live Webinar with SANS (June 25)— Agentic CTI Automation for Fun & ProfitRegister Free
Mallory
Back to intelligence
actively-exploited-vulnerabilityinternet-facing-service-vulnerabilitywidely-deployed-product-advisoryinitial-access-method

Exploitation of CVE-2026-1492 in WordPress User Registration & Membership Plugin Enables Admin Account Creation

Updated 2mo agoFirst seen Mar 5, 20264 sources

Active exploitation has been reported against CVE-2026-1492 in the User Registration & Membership WordPress plugin (WPEverest), allowing unauthenticated privilege escalation by submitting a user-controlled role value during membership registration. The flaw affects versions through 5.1.2 and enables attackers to create administrator accounts, which can then be used to install plugins/themes, modify PHP code and security settings, exfiltrate site/user data, and potentially implant malware or backdoors. Wordfence/Defiant telemetry cited in reporting indicates exploitation attempts were observed and blocked at scale in customer environments.

A fix was released in 5.1.3 (with 5.1.4 available), and the recommended mitigation is to update immediately or temporarily disable/uninstall the plugin if patching is not possible. Other WordPress plugin CVEs in the provided material—CVE-2026-1321 (Restrict Content unauth privilege escalation via rcp_level), CVE-2026-1720 (WowOptin missing authorization enabling Subscriber+ arbitrary plugin installation), and CVE-2026-2628 (All-in-One Microsoft 365 & Entra ID / Azure AD SSO Login authentication bypass)—are separate issues and should be tracked independently, as they do not describe the same exploited vulnerability affecting User Registration & Membership (CVE-2026-1492).

Share:
Exploitation of CVE-2026-1492 in WordPress User Registration & Membership Plugin Enables Admin Account Creation
Stay ahead

Get ahead of threats like this

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.

EVENT TIMELINE

How this story unfolded

5 events from the most recent confirmed update back to the earliest known activity.

5 EVENTS
Mar 5, 20264mo ago

Public reports warn CVE-2026-1492 is being actively exploited

Security outlets reported that CVE-2026-1492 was under active exploitation and affects more than 60,000 WordPress sites using the User Registration & Membership plugin. The reports urged defenders to update, remove the plugin if necessary, and audit sites for unauthorized administrator accounts.

Mar 4, 20264mo ago

Wordfence detects active exploitation attempts against customer sites

Defiant said it blocked more than 200 attempts to exploit CVE-2026-1492 in customer environments over a 24-hour period. The activity showed attackers were actively trying to create administrator accounts on vulnerable WordPress sites.

Mar 3, 20264mo ago

Wordfence receives and records CVE-2026-1492 vulnerability report

The vulnerability record states that security@wordfence.com received the CVE-2026-1492 report on March 3, 2026. The issue was documented as a critical flaw with CVSS 9.8 and linked to WordPress plugin Trac and Wordfence references.

Vendor fixes CVE-2026-1492 in User Registration & Membership 5.1.3

The plugin vendor released version 5.1.3 to restrict assignable roles during registration and remediate CVE-2026-1492. Administrators were later advised to update to the latest available version, 5.1.4, or disable the plugin if they could not patch immediately.

Researcher Foxyyy discovers privilege-escalation flaw in WordPress plugin

A critical improper privilege management vulnerability was identified in the User Registration & Membership WordPress plugin, affecting versions through 5.1.2. The flaw allows unauthenticated users to supply a privileged role during registration and create administrator accounts.

LINKED ENTITIES

Related entities

Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.

14 LINKEDOpen in app
Affected products
4 linked
WordpressApache Http ServerStripePaypal
Organizations
8 linked
LinkedinXCYFIRMAGoogleWordfenceWpeverestStripePayPal
The operational view lives in Mallory

See the full picture, correlated to your attack surface.

This page covers what’s public. Mallory adds the parts that aren’t — which of your assets are affected, which threat actors are using it right now, which detections to deploy, and what to do next.
Exposure mapping

Map indicators from this story to your assets and identify affected systems in minutes.

Threat actor evidence

Every observed campaign, victim, and pivot linked to actors named in this story.

Associated malware

Malware, exploits, and IOCs connected to the activity described here.

Detection signatures

YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.

Scheduled alerts

Get matching new stories delivered to your team as they break — not the next morning.

AI threads

Ask questions about this story and take action on the answers.