CVE-2026-1492
CRITICAL EXPLOITED NUCLEIWordPress User Registration & Membership Plugin <=5.1.2 - Privilege Escalation
Title source: llmExploitation Summary
CVE-2026-1492 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 7 public exploits from researchers including XiaomingX, limo57640-crypto, Nxploited. A Nuclei detection template is also available.
AI-analyzed exploit summary This PHP script automates the exploitation of a vulnerability in a WordPress registration system, likely involving improper nonce validation or privilege escalation. It interacts with the target site's registration form, extracts necessary tokens, and submits crafted data to elevate user privileges.
Description
The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to improper privilege management in all versions up to, and including, 5.1.2. This is due to the plugin accepting a user-supplied role during membership registration without properly enforcing a server-side allowlist. This makes it possible for unauthenticated attackers to create administrator accounts by supplying a role value during membership registration.
Exploits (7)
This PHP script automates the exploitation of a vulnerability in a WordPress registration system, likely involving improper nonce validation or privilege escalation. It interacts with the target site's registration form, extracts necessary tokens, and submits crafted data to elevate user privileges.
This repository contains a read-only scanner for detecting indicators of compromise related to CVE-2026-1492 in the WordPress User Registration & Membership plugin. It checks for plugin presence, admin account anomalies, and suspicious file patterns without exploiting the vulnerability.
This repository contains a functional exploit for CVE-2026-1492, targeting a WordPress membership plugin. The script automates user registration, membership escalation, and admin privilege acquisition through a chain of HTTP requests.
This repository contains a functional exploit for CVE-2026-1492, a privilege escalation vulnerability in the WordPress User Registration & Membership plugin. The exploit leverages improper validation of user-controlled input to assign arbitrary roles, including administrator, during the membership registration process.
The repository claims to contain a PoC for CVE-2026-1492 but only provides a vague description and a link to an external download (satoshidisk.com). No actual exploit code or technical details are included.
This PHP script automates the exploitation of CVE-2026-1492 by interacting with a WordPress registration form, extracting nonces and security tokens, and submitting crafted requests to elevate user privileges. It demonstrates an authentication bypass leading to privilege escalation.
This PHP script automates the exploitation of CVE-2026-1492 by interacting with a WordPress registration form, extracting nonces and security tokens, and submitting crafted requests to elevate a user's role to administrator. It demonstrates an authentication bypass leading to privilege escalation.
Nuclei Templates (1)
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H