CVE-2026-1492
The User Registration & Membership β Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to improper privilege management in all versions up to, and including, 5.1.2. This is due to the plugin accepting a user-supplied role during membership registration without properly enforcing a server-side allowlist. This makes it possible for unauthenticated attackers to create administrator accounts by supplying a role value during membership registration.
- Affected products
- User Registration & Membership
- CVSS 3.1
- 9.8 CRITICAL
- EPSS
- 24.2% (98th percentile)
- Weakness
- CWE-269
- NVD status
- Deferred
- Published
- 2026-03-03
CVE-2026-1492 at NVD
4 known exploits for CVE-2026-1492
Proof-of-concept code and exploit modules indexed by Sploitus