Confirms that the User Registration & Membership plugin is installed at version 5.1.2 or earlier with the membership registration AJAX handler active. The plugin accepts a user-supplied WordPress role during membership registration without server-side validation, allowing an unauthenticated attacker to register as administrator and take full control of the WordPress install.
Is your app exploitable through CVE-2026-1492?
Scan your domain free