A critical vulnerability (CVE-2026-1492) in the User Registration & Membership plugin for WordPress is being actively exploited, allowing attackers to create administrator accounts without authentication. This gives hackers full control of affected sites to steal data or distribute malware. The plugin developer has released a fixed version (5.1.3 and later), and administrators are urged to update immediately or disable the plugin. The main topics covered are the security vulnerability, its exploitation, and the recommended mitigation.