Hackers Exploit WordPress Membership Plugin Bug to Create Administrator Accounts



  • Critical flaw found in WordPress plugin that allows attackers to register administrator accounts without authenticating
  • More than 37,000 sites currently exposed

Tens of thousands of WordPress websites are vulnerable to full site takeover, thanks to a critical severity vulnerability that was just discovered in a popular plugin.

Security researchers at Defiant reported finding a bug in User Registration and Membership, a WordPress plugin that helps administrators create subscription plans, control user access, and accept payments. The error occurs because the plugin accepts user-provided roles during membership registration, without properly applying a server-side allowlist.



Leave a Comment

Your email address will not be published. Required fields are marked *