Hackers can now take over WordPress sites instantly using a simple plugin flaw that exposes admin access without requiring login credentials

Hackers can now take over WordPress sites instantly using a simple plugin flaw that exposes admin access without requiring login credentials | Daily Reports Online

Share


  • User Registration & Membership plugin flaw allows attackers to gain admin access without login
  • Exposed nonce values enable unauthorized backend requests and privilege escalation
  • Sensitive user data becomes exposed once administrative privileges are obtained

A critical security flaw in a widely used WordPress plugin allows unauthenticated attackers to bypass authentication controls and gain full administrative access to affected websites.


The vulnerability, tracked as CVE-2026-1492, affects the User Registration & Membership plugin, versions 5.1.2 and earlier.


Similar Posts