Story perspectives
Critical WordPress Flaw Exposes 37,000 Sites to Attack
3/6/2026
1 of 1
Story summary
- Defiant security researchers found a critical vulnerability in the WordPress User Registration & Membership plugin that lets unauthenticated attackers create admin accounts (CVE-2026-1492, severity 9.8/10).
- Over 37,000 websites are affected, and the flaw is being actively exploited with about 200 attempts in 24 hours.
- The vulnerability affects all versions up to 5.1.2, with a fix in 5.1.3.
- Exploitation can exfiltrate data, host malware, or redirect traffic to malicious sites.
