S4E just found a high top 10 tcp port service scan
critical·Product Based Web Vulnerabilities·Updated Mar 12, 2026

CVE-2026-1492 Scanner

CVE-2026-1492 Scanner - Privilege Escalation vulnerability in WordPress User Registration & Membership Plugin

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
0
Times Used
by S4E users
0
Assets Scanned
domains & IPs
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2026-1492
9.8
CVSScritical
Exploitable remotely over the internet · no authentication required.

The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to improper privilege management in all versions up to, and including, 5.1.2. This is due to the plugin accepting a user-supplied role during membership registration without properly enforcing a server-side allowlist. This makes it possible for unauthenticated attackers to create administrator accounts by supplying a role value during membership registration.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builderby wpeverest
0
Updated Aug 22, 2026View on NVD →
Detail

The WordPress User Registration & Membership Plugin is widely used by website administrators to manage user registrations and memberships. It helps in handling user roles, providing customized membership plans, and supports various registration forms. Developed for WordPress websites, this plugin plays a crucial role in extending user management capabilities. It's commonly used by sites that require flexible membership structures and detailed user management processes. With its set of features, the plugin assists in providing a streamlined experience for both administrators and users. Overall, it is a pivotal tool for WordPress-based communities and membership sites.

The privilege escalation vulnerability in the WordPress User Registration & Membership Plugin arises from the lack of server-side enforcement on user-supplied role assignments. Without proper validation and restrictions, malicious actors can exploit this to gain administrative access. The vulnerability allows unauthenticated users to create accounts with elevated privileges, which can undermine site security. By exploiting this flaw, attackers may gain unauthorized control over the WordPress site's functionalities. It represents a severe threat, particularly to sites that heavily rely on user role segregation for their operational integrity. The susceptibility is most prevalent in versions 5.1.2 and earlier of the plugin.

In technical terms, the vulnerability stems from the user registration process where roles are accepted without adequate allowlist checks. The endpoint for account creation evaluates user roles supplied during registration but fails to strictly enforce permissible roles. Attackers can submit requests to assign themselves administrative roles by manipulating the form data. The plugin's failure in consistently enforcing role restrictions enables attackers to circumvent normal procedures. Parameters such as `form_id` and `user_registration_form_data_save` are involved, though not adequately safeguarded. This lack of stringent validation exposes a critical vector for potential system compromise.

If exploited, this vulnerability can have serious consequences, including unauthorized site management and data exposure. Malicious actors could manipulate site content, access sensitive user information, or disrupt site operations. Unauthorized admins could install malicious plugins or alter site configurations, leading to further vulnerabilities. It contravenes security principles, ultimately compromising site integrity and user trust. Full system compromise could result in financial losses, especially for businesses relying on their WordPress sites. Proactive measures are imperative to prevent potential exploits and maintain operational security.

REFERENCES

Solution Advice
  • Update the WordPress User Registration & Membership Plugin to a version beyond 5.1.2.
  • Regularly audit plugins and themes for potential security vulnerabilities.
  • Implement server-side user role validation and enforce role restrictions effectively.
  • Restrict the capability of role assignment to trusted users with legitimate access.
  • Monitor security advisories related to WordPress plugins and apply updates promptly.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.