All verified exploits

CVE-2026-1492 Unauthenticated Privilege Escalation to Administrator

Deterministic critical User Registration Added cve-verified-cve-2026-1492

Confirms that the User Registration & Membership plugin is installed at version 5.1.2 or earlier with the membership registration AJAX handler active. The plugin accepts a user-supplied WordPress role during membership registration without server-side validation, allowing an unauthenticated attacker to register as administrator and take full control of the WordPress install.

Is your app exploitable through CVE-2026-1492?

Scan your domain free