Hackers can now take over WordPress sites instantly using a simple plugin that exposes admin access without requiring login credentials.



  • User Registration and Membership Plugin Flaw Allows Attackers to Gain Admin Access Without Login
  • Exposed nonce values ​​allow unauthorized backend requests and privilege escalation
  • Sensitive user data is exposed once administrative privileges are gained

A critical security flaw in a widely used WordPress plugin allows unauthenticated attackers to bypass authentication controls and gain full administrative access to affected websites.

The vulnerability, identified as CVE-2026-1492, affects the User and Membership Registration plugin, versions 5.1.2 and earlier.

Leave a Comment

Your email address will not be published. Required fields are marked *