• News/
  • https://www.bleepingcomputer.com/news/security/wordpress-membership-plugin-bug-exploited-to-create-admin-accounts/

WordPress membership plugin bug exploited to create admin accounts

BleepingComputer
·
Bill Toulas
·
Published Mar 5, 2026
·
Updated

Hackers are exploiting a critical vulnerability in the User Registration & Membership plugin, which is installed on more than 60,000 WordPress sites. Developed by WPEverest, the plugin provides membership and user registration management features, including custom forms, payment integrations with PayPal and Stripe, bank transfers, and analytics. The security vulnerability is tracked as CVE-2026-1492 and received a critical severity rating of 9.8. Because the plugin accepts a user-supplied role during membership registration, hackers can create administrator accounts without authentication. An administrator account has full access on the website, and it is required to install plugins and themes, edit PHP code, change security settings, modify site content, and lock out legitimate owners or admins. An attacker with this level of access can steal data, such as the database of registered users, and embed malicious code to distribute malware to visitors. Researchers at WordPress security company Defiant, the maker of the Wordfence security plugin, blocked more than 200 attempts to exploit CVE-2026-1492 in customer environments in the past 24 hours. The vulnerability affects all versions of User Registration & Membership through 5.1.2. The developer released a fix in version 5.1.3 of the plugin. Website admins are advised to update to the latest version of the plugin, which is currently 5.1.4, released last week. If updating is not possible, the recommendation is to temporarily di...

Read full article

Affected Software

1 affected component
WPEverest User Registration & Membership<=5.1.2
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses a critical vulnerability in the WPEverest User Registration & Membership plugin that is being exploited to create unauthorized admin accounts.

2

What security implications are discussed?

The vulnerability allows hackers to gain admin access to WordPress sites, potentially compromising sensitive data and site integrity.

3

What products or software are affected?

The affected software is the WPEverest User Registration & Membership plugin, specifically versions up to 5.1.2.

4

How many WordPress sites are affected by this vulnerability?

The vulnerability affects more than 60,000 WordPress sites using the plugin.

5

Who developed the User Registration & Membership plugin?

The plugin is developed by WPEverest.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203