Active exploitation has been reported against CVE-2026-1492 in the User Registration & Membership WordPress plugin (WPEverest), allowing unauthenticated privilege escalation by submitting a user-controlled role value during membership registration. The flaw affects versions through 5.1.2 and enables attackers to create administrator accounts, which can then be used to install plugins/themes, modify PHP code and security settings, exfiltrate site/user data, and potentially implant malware or backdoors. Wordfence/Defiant telemetry cited in reporting indicates exploitation attempts were observed and blocked at scale in customer environments.
A fix was released in 5.1.3 (with 5.1.4 available), and the recommended mitigation is to update immediately or temporarily disable/uninstall the plugin if patching is not possible. Other WordPress plugin CVEs in the provided material—CVE-2026-1321 (Restrict Content unauth privilege escalation via rcp_level), CVE-2026-1720 (WowOptin missing authorization enabling Subscriber+ arbitrary plugin installation), and CVE-2026-2628 (All-in-One Microsoft 365 & Entra ID / Azure AD SSO Login authentication bypass)—are separate issues and should be tracked independently, as they do not describe the same exploited vulnerability affecting User Registration & Membership (CVE-2026-1492).

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
5 events from the most recent confirmed update back to the earliest known activity.
Security outlets reported that CVE-2026-1492 was under active exploitation and affects more than 60,000 WordPress sites using the User Registration & Membership plugin. The reports urged defenders to update, remove the plugin if necessary, and audit sites for unauthorized administrator accounts.
Defiant said it blocked more than 200 attempts to exploit CVE-2026-1492 in customer environments over a 24-hour period. The activity showed attackers were actively trying to create administrator accounts on vulnerable WordPress sites.
The vulnerability record states that security@wordfence.com received the CVE-2026-1492 report on March 3, 2026. The issue was documented as a critical flaw with CVSS 9.8 and linked to WordPress plugin Trac and Wordfence references.
The plugin vendor released version 5.1.3 to restrict assignable roles during registration and remediate CVE-2026-1492. Administrators were later advised to update to the latest available version, 5.1.4, or disable the plugin if they could not patch immediately.
A critical improper privilege management vulnerability was identified in the User Registration & Membership WordPress plugin, affecting versions through 5.1.2. The flaw allows unauthenticated users to supply a privileged role during registration and create administrator accounts.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
4 references tracked. Mallory keeps watching after this page renders.
cybersecuritynews.com
Open sourcecybersecuritynews.com
Open sourcebleepingcomputer.com
Open sourcecvefeed.io
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.