CVE-2026-1492: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-1492 is a critical improper privilege management vulnerability in the User Registration & Membership WordPress plugin (by WPEverest), affecting all versions up to and including 5.1.2. The flaw allows unauthenticated attackers to create administrator accounts by supplying an arbitrary role value during membership registration, as the plugin fails to enforce a server-side allowlist. It was disclosed on March 3, 2026, and carries a CVSS v3.1 base score of 9.8 (Critical) (Wordfence, Red Hat CVE).

Technical details

The root cause is CWE-269 (Improper Privilege Management): the plugin's membership registration handler accepts a user-controlled role parameter and assigns it directly to the newly created account without validating it against a server-side allowlist of permitted roles. An unauthenticated attacker can craft a registration request that includes role=administrator (or equivalent), causing WordPress to create a fully privileged admin account. No authentication, special configuration, or user interaction is required — the attack is fully remote and low-complexity (Wordfence, ENISA EUVD). Public PoC repositories have been published on GitHub (GitHub PoC 1, GitHub PoC 2, GitHub PoC 3).

Impact

Successful exploitation grants an attacker full WordPress administrator access, enabling complete site takeover. Consequences include data theft (user PII, credentials, payment data), malware or backdoor deployment, website defacement, SEO spam injection, and lateral movement to the underlying hosting infrastructure. All three CIA pillars are critically affected, and the impact extends to every site visitor and any connected systems (BleepingComputer, Wordfence).

Exploitability

Active in-the-wild exploitation has been confirmed, with attackers leveraging the flaw to create hidden administrator accounts on vulnerable WordPress sites (BleepingComputer). Multiple public PoC exploits are available on GitHub, and Nuclei detection templates have been added to ProjectDiscovery's template library (GitHub Nuclei Templates). The plugin had over 60,000–200,000 active installations at the time of disclosure, making the attack surface significant (TechRadar). The EPSS score is approximately 0.074% (low automated exploitation probability), but real-world exploitation has been independently reported. No CISA KEV listing has been confirmed in the available data.

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the User Registration & Membership plugin (versions ≤ 5.1.2) using tools like WPScan, Shodan, or by inspecting page source for plugin fingerprints (e.g., /wp-content/plugins/user-registration/).
  2. Locate the registration endpoint: Navigate to the site's membership registration form, typically at /register/ or a custom page using the plugin's registration shortcode.
  3. Intercept the registration request: Use a proxy tool (e.g., Burp Suite) to capture the HTTP POST request submitted when filling out the registration form.
  4. Inject the administrator role: Add or modify the role parameter in the POST body to administrator (e.g., role=administrator), alongside valid values for required fields (username, email, password).
  5. Submit the crafted request: Send the modified request to the server. The plugin processes the user-supplied role without validation and creates the account with administrator privileges.
  6. Log in as administrator: Use the newly created credentials to log into /wp-admin/, gaining full control of the WordPress site for further actions such as installing plugins, exfiltrating data, or deploying webshells (BleepingComputer, Wordfence).

Indicators of compromise

  • Network: Unusual POST requests to the plugin's registration endpoint (e.g., /register/, /wp-login.php?action=register, or custom registration pages) containing a role=administrator or similar elevated role parameter in the body.
  • Logs: WordPress access logs showing registration requests with unexpected role field values; multiple new user registrations in a short timeframe from the same or rotating IP addresses.
  • WordPress Admin Panel: Presence of unexpected administrator accounts, especially those with generic or randomized usernames/emails not matching legitimate users; accounts created outside normal business hours.
  • File System: New or modified PHP files in the WordPress uploads directory or plugin folders (indicating post-exploitation webshell deployment); changes to wp-config.php or .htaccess.
  • Process/Behavior: Unusual outbound connections from the web server process; execution of system commands via the web server user account following admin account creation (BleepingComputer, Wordfence).

Mitigation and workarounds

Immediately update the User Registration & Membership plugin to a version newer than 5.1.2; the patch was committed to the WordPress plugin repository (changeset 3469042) (WordPress SVN). If an immediate update is not possible, temporarily deactivate the plugin to prevent exploitation. After patching, audit all WordPress administrator accounts and remove any unauthorized ones created during the exposure window. Review registration logs for suspicious activity and consider implementing a web application firewall (WAF) rule to block POST requests containing elevated role values to registration endpoints (Wordfence, Sucuri Blog).

Community reactions

Wordfence, which discovered and reported the vulnerability, published a detailed threat intelligence entry and included it in their weekly WordPress vulnerability report for March 2–8, 2026 (Wordfence Blog). BleepingComputer reported confirmed in-the-wild exploitation, drawing significant community attention (BleepingComputer). The Hacker News included it in their weekly recap, and the story was widely shared across LinkedIn, Mastodon, Bluesky, and Reddit security communities. Check Point Research also referenced the vulnerability in their March 9 threat intelligence report (Check Point Research). TechRadar highlighted the risk to over 60,000 websites, amplifying urgency for patching (TechRadar).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management