Skip to content

CVE-2026-1492

CVE

Threat entity extracted from intelligence sources

Frequency
5
occurrences
First Seen
March 5, 2026
Last Seen
April 13, 2026
API
Exploited in Wild
Ransomware Use
Public Exploits
Attack Vector

Vulnerability Overview

Exploitation Activity

Exploitation Intelligence

A critical vulnerability, tracked as CVE-2026-1492, has been discovered in the User Registration & Membership plugin for WordPress. This flaw enables remote attackers to bypass authentication and gain full administrative access without valid credentials. The vulnerability affects versions up to 5.1....

A critical vulnerability (CVE-2026-1492) in the User Registration & Membership plugin, used by over 60,000 WordPress sites, is being actively exploited by hackers to create unauthorized admin accounts. The vulnerability has a severity rating of 9.8, indicating a significant risk to affected sites, w...

Public Exploits

Checking GitHub for proof-of-concept code…