Exploitation of CVE-2026-1492 in WordPress User Registration & Membership Plugin Enables Admin Account Creation
Active exploitation has been reported against CVE-2026-1492 in the User Registration & Membership WordPress plugin (WPEverest), allowing unauthenticated privilege escalation by submitting a user-controlled role value during membership registration. The flaw affects versions through 5.1.2 and enables attackers to create administrator accounts, which can then be used to install plugins/themes, modify PHP code and security settings, exfiltrate site/user data, and potentially implant malware or backdoors. Wordfence/Defiant telemetry cited in reporting indicates exploitation attempts were observed and blocked at scale in customer environments.
A fix was released in 5.1.3 (with 5.1.4 available), and the recommended mitigation is to update immediately or temporarily disable/uninstall the plugin if patching is not possible. Other WordPress plugin CVEs in the provided material—CVE-2026-1321 (Restrict Content unauth privilege escalation via rcp_level), CVE-2026-1720 (WowOptin missing authorization enabling Subscriber+ arbitrary plugin installation), and CVE-2026-2628 (All-in-One Microsoft 365 & Entra ID / Azure AD SSO Login authentication bypass)—are separate issues and should be tracked independently, as they do not describe the same exploited vulnerability affecting User Registration & Membership (CVE-2026-1492).

Get ahead of threats like this
Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
How this story unfolded
5 events from the most recent confirmed update back to the earliest known activity.
Public reports warn CVE-2026-1492 is being actively exploited
Security outlets reported that CVE-2026-1492 was under active exploitation and affects more than 60,000 WordPress sites using the User Registration & Membership plugin. The reports urged defenders to update, remove the plugin if necessary, and audit sites for unauthorized administrator accounts.
Wordfence detects active exploitation attempts against customer sites
Defiant said it blocked more than 200 attempts to exploit CVE-2026-1492 in customer environments over a 24-hour period. The activity showed attackers were actively trying to create administrator accounts on vulnerable WordPress sites.
Wordfence receives and records CVE-2026-1492 vulnerability report
The vulnerability record states that security@wordfence.com received the CVE-2026-1492 report on March 3, 2026. The issue was documented as a critical flaw with CVSS 9.8 and linked to WordPress plugin Trac and Wordfence references.
Vendor fixes CVE-2026-1492 in User Registration & Membership 5.1.3
The plugin vendor released version 5.1.3 to restrict assignable roles during registration and remediate CVE-2026-1492. Administrators were later advised to update to the latest available version, 5.1.4, or disable the plugin if they could not patch immediately.
Researcher Foxyyy discovers privilege-escalation flaw in WordPress plugin
A critical improper privilege management vulnerability was identified in the User Registration & Membership WordPress plugin, affecting versions through 5.1.2. The flaw allows unauthenticated users to supply a privileged role during registration and create administrator accounts.
Related entities
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Sources
4 references tracked. Mallory keeps watching after this page renders.
Critical WordPress Plugin Flaw Lets Attackers Bypass Authentication and Gain Admin Access
cybersecuritynews.com
Open sourceWordPress Membership Plugin Vulnerability Let Attackers Create Admin Accounts
cybersecuritynews.com
Open sourceWordPress membership plugin bug exploited to create admin accounts
bleepingcomputer.com
Open sourceCVE-2026-1492 - User Registration & Membership <= 5.1.2 - Unauthenticated Privilege Escalation via Membership Registration
cvefeed.io
Open sourceSee the full picture, correlated to your attack surface.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.


