Hackers can now take over WordPress sites instantly using a simple plugin flaw that exposes admin access without requiring login credentials


  • User registration and membership plugin flaws allow attackers to gain administrator access without logging in
  • Exposed nonce values ​​enable unauthorized backend requests and privilege escalation
  • Sensitive user data is revealed when the administrative rights are obtained

A critical security flaw in a widespread WordPress plugin allows unauthorized attackers to bypass authentication checks and gain full administrative access to affected websites.

The vulnerability, tracked as CVE-2026-1492, affects the User Registration and Membership plugin version 5.1.2 and earlier.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top