User Registration & Membership WordPress plugin <= 5.1.2 contains an improper privilege management vulnerability caused by accepting user-supplied roles without server-side allowlist enforcement, letting unauthenticated attackers create administrator accounts
id: CVE-2026-1492
info:
name: WordPress User Registration & Membership <= 5.1.2 - Unauthenticated
...