Image for Article: WordPress membership plugin bug exploited to create admin accounts

Article Details

Title
Article: WordPress membership plugin bug exploited to create admin accounts
Impact Score
6 / 10
AI Summary (Processed Content)

A critical vulnerability (CVE-2026-1492) in the User Registration & Membership plugin for WordPress is being actively exploited, allowing attackers to create administrator accounts without authentication. This gives hackers full control of affected sites to steal data or distribute malware. The plugin developer has released a fixed version (5.1.3 and later), and administrators are urged to update immediately or disable the plugin. The main topics covered are the security vulnerability, its exploitation, and the recommended mitigation.

Original URL
https://www.bleepingcomputer.com/news/security/wordpress-membership-plugin-bug-exploited-to-create-admin-accounts/
Source Feed
BleepingComputer
Published Date
2026-03-05 18:44
Fetched Date
2026-03-05 15:45
Processed Date
2026-03-05 15:45
Embedding Status
Present
Cluster ID
Not Clustered
Raw Extracted Content