Hackers can now instantly take control of WordPress sites using a simple plugin flaw that exposes admin access without requiring login credentials.


  • Flaw in User Registration & Membership plugin allows attackers to gain administrator access without login
  • Exposed casual values ​​allow unauthorized backend requests and privilege escalation
  • Sensitive user data is exposed after administrative privileges are gained

A critical security flaw in a widely used WordPress plugin allows unauthenticated attackers to bypass authentication controls and gain full administrative access to affected websites.

The vulnerability, identified as CVE-2026-1492, affects the User Registration & Membership plugin, versions 5.1.2 and earlier.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top