
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-1492 is a critical improper privilege management vulnerability in the User Registration & Membership WordPress plugin (by WPEverest), affecting all versions up to and including 5.1.2. The flaw allows unauthenticated attackers to create administrator accounts by supplying an arbitrary role value during membership registration, as the plugin fails to enforce a server-side allowlist. It was disclosed on March 3, 2026, and carries a CVSS v3.1 base score of 9.8 (Critical) (Wordfence, Red Hat CVE).
The root cause is CWE-269 (Improper Privilege Management): the plugin's membership registration handler accepts a user-controlled role parameter and assigns it directly to the newly created account without validating it against a server-side allowlist of permitted roles. An unauthenticated attacker can craft a registration request that includes role=administrator (or equivalent), causing WordPress to create a fully privileged admin account. No authentication, special configuration, or user interaction is required — the attack is fully remote and low-complexity (Wordfence, ENISA EUVD). Public PoC repositories have been published on GitHub (GitHub PoC 1, GitHub PoC 2, GitHub PoC 3).
Successful exploitation grants an attacker full WordPress administrator access, enabling complete site takeover. Consequences include data theft (user PII, credentials, payment data), malware or backdoor deployment, website defacement, SEO spam injection, and lateral movement to the underlying hosting infrastructure. All three CIA pillars are critically affected, and the impact extends to every site visitor and any connected systems (BleepingComputer, Wordfence).
Active in-the-wild exploitation has been confirmed, with attackers leveraging the flaw to create hidden administrator accounts on vulnerable WordPress sites (BleepingComputer). Multiple public PoC exploits are available on GitHub, and Nuclei detection templates have been added to ProjectDiscovery's template library (GitHub Nuclei Templates). The plugin had over 60,000–200,000 active installations at the time of disclosure, making the attack surface significant (TechRadar). The EPSS score is approximately 0.074% (low automated exploitation probability), but real-world exploitation has been independently reported. No CISA KEV listing has been confirmed in the available data.
/wp-content/plugins/user-registration/)./register/ or a custom page using the plugin's registration shortcode.role parameter in the POST body to administrator (e.g., role=administrator), alongside valid values for required fields (username, email, password)./wp-admin/, gaining full control of the WordPress site for further actions such as installing plugins, exfiltrating data, or deploying webshells (BleepingComputer, Wordfence)./register/, /wp-login.php?action=register, or custom registration pages) containing a role=administrator or similar elevated role parameter in the body.role field values; multiple new user registrations in a short timeframe from the same or rotating IP addresses.wp-config.php or .htaccess.Immediately update the User Registration & Membership plugin to a version newer than 5.1.2; the patch was committed to the WordPress plugin repository (changeset 3469042) (WordPress SVN). If an immediate update is not possible, temporarily deactivate the plugin to prevent exploitation. After patching, audit all WordPress administrator accounts and remove any unauthorized ones created during the exposure window. Review registration logs for suspicious activity and consider implementing a web application firewall (WAF) rule to block POST requests containing elevated role values to registration endpoints (Wordfence, Sucuri Blog).
Wordfence, which discovered and reported the vulnerability, published a detailed threat intelligence entry and included it in their weekly WordPress vulnerability report for March 2–8, 2026 (Wordfence Blog). BleepingComputer reported confirmed in-the-wild exploitation, drawing significant community attention (BleepingComputer). The Hacker News included it in their weekly recap, and the story was widely shared across LinkedIn, Mastodon, Bluesky, and Reddit security communities. Check Point Research also referenced the vulnerability in their March 9 threat intelligence report (Check Point Research). TechRadar highlighted the risk to over 60,000 websites, amplifying urgency for patching (TechRadar).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."