Hackers can now take over WordPress sites instantly using a simple plugin flaw that exposes admin access without requiring login credentials



  • User Registration & Membership plugin flaw allows attackers to gain admin access without login
  • Exposed nonce values enable unauthorized backend requests and privilege escalation
  • Sensitive user data becomes exposed once administrative privileges are obtained

A critical security flaw in a widely used WordPress plugin allows unauthenticated attackers to bypass authentication controls and gain full administrative access to affected websites.

The vulnerability, tracked as CVE-2026-1492, affects the User Registration & Membership plugin, versions 5.1.2 and earlier.

https://cdn.mos.cms.futurecdn.net/PxxKy74xA4GapoubYuoRtK-2560-80.jpg



Source link

Latest articles

spot_imgspot_img

Related articles

Leave a reply

Please enter your comment!
Please enter your name here

spot_imgspot_img