CVE-2026-1492

CRITICAL EXPLOITED NUCLEI

WordPress User Registration & Membership Plugin <=5.1.2 - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2026-1492 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 7 public exploits from researchers including XiaomingX, limo57640-crypto, Nxploited. A Nuclei detection template is also available.

AI-analyzed exploit summary This PHP script automates the exploitation of a vulnerability in a WordPress registration system, likely involving improper nonce validation or privilege escalation. It interacts with the target site's registration form, extracts necessary tokens, and submits crafted data to elevate user privileges.

Description

The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to improper privilege management in all versions up to, and including, 5.1.2. This is due to the plugin accepting a user-supplied role during membership registration without properly enforcing a server-side allowlist. This makes it possible for unauthenticated attackers to create administrator accounts by supplying a role value during membership registration.

Exploits (7)

github WORKING POC 10 stars
by XiaomingX · pythonpoc
https://github.com/XiaomingX/data-cve-poc-py-v1/tree/main/2026/CVE-2026-1492

This PHP script automates the exploitation of a vulnerability in a WordPress registration system, likely involving improper nonce validation or privilege escalation. It interacts with the target site's registration form, extracts necessary tokens, and submits crafted data to elevate user privileges.

Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: WordPress with User Registration plugin (version unspecified)
No auth needed
Prerequisites: Target site URL · Registration page URL · WordPress installation with vulnerable User Registration plugin
devstral-2 · analyzed Mar 08, 2026 Full analysis →
nomisec SCANNER
by limo57640-crypto · poc
https://github.com/limo57640-crypto/wp-user-registration-vuln-checker

This repository contains a read-only scanner for detecting indicators of compromise related to CVE-2026-1492 in the WordPress User Registration & Membership plugin. It checks for plugin presence, admin account anomalies, and suspicious file patterns without exploiting the vulnerability.

Classification
Scanner 95%
Attack Type
Info Leak
Complexity
Moderate
Reliability
Reliable
Target: WordPress User Registration & Membership plugin
No auth needed
Prerequisites: WordPress installation with wp-config.php · mysql client for database queries
devstral-2 · analyzed Jun 08, 2026 Full analysis →
nomisec WORKING POC
by Nxploited · remote
https://github.com/Nxploited/CVE-2026-1492

This repository contains a functional exploit for CVE-2026-1492, targeting a WordPress membership plugin. The script automates user registration, membership escalation, and admin privilege acquisition through a chain of HTTP requests.

Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: WordPress Membership Plugin (version not specified)
No auth needed
Prerequisites: Target URL with vulnerable WordPress membership plugin
devstral-2 · analyzed Apr 18, 2026 Full analysis →
nomisec WORKING POC
by the8frust · remote
https://github.com/the8frust/CVE-2026-1492

This repository contains a functional exploit for CVE-2026-1492, a privilege escalation vulnerability in the WordPress User Registration & Membership plugin. The exploit leverages improper validation of user-controlled input to assign arbitrary roles, including administrator, during the membership registration process.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: WordPress User Registration & Membership plugin <= 5.1.2
No auth needed
Prerequisites: Target WordPress site with vulnerable plugin installed · Access to the registration page
devstral-2 · analyzed Mar 21, 2026 Full analysis →
nomisec SUSPICIOUS
by DeadExpl0it · poc
https://github.com/DeadExpl0it/CVE-2026-1492

The repository claims to contain a PoC for CVE-2026-1492 but only provides a vague description and a link to an external download (satoshidisk.com). No actual exploit code or technical details are included.

Classification
Suspicious 95%
Attack Type
Other
Complexity
Theoretical
Reliability
Theoretical
Target: unspecified
No auth needed
Prerequisites: none specified
devstral-2 · analyzed Mar 10, 2026 Full analysis →
nomisec WORKING POC
by imad-z1 · poc
https://github.com/imad-z1/CVE-2026-1492-POC

This PHP script automates the exploitation of CVE-2026-1492 by interacting with a WordPress registration form, extracting nonces and security tokens, and submitting crafted requests to elevate user privileges. It demonstrates an authentication bypass leading to privilege escalation.

Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: WordPress with User Registration plugin
No auth needed
Prerequisites: WordPress site with vulnerable User Registration plugin · Access to registration endpoint
devstral-2 · analyzed Apr 17, 2026 Full analysis →
nomisec WORKING POC
by dreamboyim66-boop · poc
https://github.com/dreamboyim66-boop/CVE-2026-1492-POC

This PHP script automates the exploitation of CVE-2026-1492 by interacting with a WordPress registration form, extracting nonces and security tokens, and submitting crafted requests to elevate a user's role to administrator. It demonstrates an authentication bypass leading to privilege escalation.

Classification
Working Poc 90%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: WordPress with User Registration plugin (version not specified)
No auth needed
Prerequisites: WordPress site with vulnerable User Registration plugin · Registration form accessible
devstral-2 · analyzed Mar 07, 2026 Full analysis →

Nuclei Templates (1)

WordPress User Registration & Membership <= 5.1.2 - Unauthenticated Privilege Escalation
CRITICALVERIFIEDby omarkurt

Scores

CVSS v3 9.8
EPSS 0.2477
EPSS Percentile 96.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact total

Details

VulnCheck KEV 2026-03-02
CWE
CWE-269
Status published
Products (1)
wpeverest/User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder < 5.1.2
Published Mar 03, 2026
Tracked Since Mar 03, 2026