Hackers exploit WordPress membership plugin bug to create admin accounts


  • Critical flaw found in WordPress plugin allowing attackers to register unauthenticated administrator accounts
  • More than 37,000 sites currently exposed

Tens of thousands of WordPress websites are vulnerable to a complete site takeover, thanks to a recently discovered critical severity vulnerability in a popular plugin.

Defiant security researchers reported discovering a bug in User Registration & Membership, a WordPress plugin that helps administrators create subscription plans, control user access, and accept payments. The bug is caused by the plugin accepting user-provided roles when registering members, without properly applying a server-side allowlist.

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top