HomeSecurityWordPress: Vulnerability in the User Registration & Membership plugin

WordPress: Vulnerability in the User Registration & Membership plugin

A particularly serious security vulnerability has been identified in the User Registration & Membership plugin for WordPress , causing concern among the website administrator community. The vulnerability, tracked as CVE-2026-1492 , allows malicious users to bypass basic protection mechanisms and gain administrative privileges on a website, without requiring prior authentication.

WordPress: Vulnerability in the User Registration & Membership plugin

User Registration & Membership is widely used to create user registration forms, manage accounts , and create custom profiles on WordPress websites. Thousands of websites rely on this plugin to manage members, subscribers, and user communities.

See also: CISA: Hikvision and Rockwell Automation vulnerabilities in the KEV Catalog

User Registration & Membership: How the CVE-2026-1492 vulnerability works

The vulnerability affects all versions of the plugin up to version 5.1.2 and is related to incorrect user rights management during the registration process. Specifically, when a new user fills out the registration form, the system accepts the user role sent in the request, without checking whether this role is actually allowed by the server.

This means that an attacker can modify the registration request and declare the role as “administrator.” Since the plugin does not have a server-side allowlist, the system accepts the role and creates an account with full administrative privileges.

Complete WordPress site takeover

Successful exploitation of the vulnerability could lead to complete control of a WordPress website. An attacker with administrative privileges could modify content, install malicious plugins, create hidden accounts, or introduce backdoors for future access.

See also: Cisco: Two vulnerabilities in Catalyst SD-WAN Manager actively exploited

Additionally, it can gain access to sensitive user data, such as email addresses, personal information, or even payment information, depending on the functionality of the site. This makes this vulnerability particularly dangerous for online stores, membership sites, and community platforms.

WordPress: Vulnerability in the User Registration & Membership plugin

Active attacks on the internet

The vulnerability was discovered by security researcher Foxyyy and has received a CVSS score of 9.8, which is considered critical. According to data from website protection systems, active attempts to exploit the problem have already been recorded.

In just 24 hours, security mechanisms managed to block more than 70 attack attempts targeting websites with vulnerable versions of the plugin, indicating that the vulnerability has already attracted the attention of cybercriminals looking for easy targets online.

Second serious security issue in the same plugin

As if that weren't enough, experts have also identified a second serious security issue in the same plugin. The CVE-2026-1779 allows for a complete bypass of the authentication process, allowing attackers to bypass the login mechanism.

The coexistence of two critical vulnerabilities in the same plugin significantly increases the risk for websites that rely on it, as it offers multiple entry points for potential attackers.

See also: MongoDB: Vulnerability allows servers to crash

Security update available

The plugin vendor has already released a version that addresses the issue. The update limits the roles that can be assigned during the registration process and implements server-side validation.

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

This prevents users from being assigned arbitrary roles and eliminates the privilege escalation scenario. The vulnerability was publicly disclosed on March 2, 2026, and the relevant fix was released the following day.

Website administrators are urged to immediately upgrade the plugin to version 5.1.3 or laterin order to protect their platforms.

WordPress: Vulnerability in the User Registration & Membership plugin

What WordPress administrators should do immediately

Cybersecurity experts recommend that website administrators take immediate protective actions. The first step is to update the plugin to the latest available version.

It is then recommended to perform a full audit of existing user accounts to identify possible administrator accounts that were created without authorization.

At the same time, it is a good idea to enable activity monitoring on registration forms, in order to identify suspicious requests or unusual attempts to create accounts with elevated privileges.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS