Skip to content
Critical Vulnerability in WordPress Plugin Exploited for Unauthorized Admin Access

Critical Vulnerability in WordPress Plugin Exploited for Unauthorized Admin Access

First seen 5 Mar 2026, 19:12 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •March 12, 2026 at 16:10 UTC

A critical vulnerability (CVE-2026-1492) in the User Registration & Membership plugin, used by over 60,000 WordPress sites, is being actively exploited by hackers to create unauthorized admin accounts. The vulnerability has a severity rating of 9.8, indicating a significant risk to affected sites, which can lead to unauthorized access and control.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated 212d ago How this analysis works

Timeline

2026-01-14
CVE-2026-23550 published
2026-01-16
First public PoC for CVE-2026-23550
2026-03-03
CVE-2026-1492 published
2026-03-05
Active exploitation reported in the wild

More articles in this cluster (8)

Following this threat?

Track CVE-2026-1492 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed