Hackers Exploiting WordPress Membership Plugin Flaw to Create Admin Accounts


  • Critical bug found in WordPress plugin that allows attackers to register admin accounts without authorization
  • Over 37,000 websites are currently exposed

Tens of thousands of WordPress websites are vulnerable to a site-wide takeover, thanks to a critical vulnerability just discovered in a popular plugin.

Security researchers at Defiant reported finding a flaw in User Registration & Membership, a WordPress plugin that helps administrators create subscription plans, control user access, and accept payments. The error is caused by the plugin accepting user-supplied roles during membership registration without properly enforcing a server-side permission list.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top