← Back to browse · API

CVE-2026-1492

Severity
CRITICAL
CVSS
9.8
EPSS
0.24229
Risk score
47.68
CISA KEV
No
PoC
Yes
Published
2026-03-03
Modified
2026-04-08
First seen
2026-08-07
Aliases
EUVD-2026-9277, GHSA-6GHQ-4J9P-H2V9
Products
WPEverest:User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder 0 ≤5.1.2
Sources
euvd EUVD-2026-9277
packetstorm e1b15243aca2ad53b47ce4cf|CVE-2026-1492

Description

The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to improper privilege management in all versions up to, and including, 5.1.2. This is due to the plugin accepting a user-supplied role during membership registration without properly enforcing a server-side allowlist. This makes it possible for unauthenticated attackers to create administrator accounts by supplying a role value during membership registration.

References