By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
MadisonyMadisony
Notification Show More
Font ResizerAa
  • Home
  • National & World
  • Politics
  • Investigative Reports
  • Education
  • Health
  • Entertainment
  • Technology
  • Sports
  • Money
  • Pets & Animals
Reading: Update Now: 60K WordPress Sites Face Admin Hack Risk
Share
Font ResizerAa
MadisonyMadisony
Search
  • Home
  • National & World
  • Politics
  • Investigative Reports
  • Education
  • Health
  • Entertainment
  • Technology
  • Sports
  • Money
  • Pets & Animals
Have an existing account? Sign In
Follow US
2025 © Madisony.com. All Rights Reserved.
Technology

Update Now: 60K WordPress Sites Face Admin Hack Risk

Madisony
Last updated: April 18, 2026 9:15 pm
Madisony
Share
Update Now: 60K WordPress Sites Face Admin Hack Risk
SHARE

A critical security vulnerability in the User Registration & Membership plugin threatens over 60,000 WordPress websites, enabling hackers to create hidden admin accounts without authentication. Tracked as CVE-2026-1492, the flaw affects versions up to 5.1.2 and stems from inadequate server-side validation and weak authorization in the membership workflow.

Contents
How Attackers Exploit the FlawPotential Impacts of ExploitationRemediation Steps

How Attackers Exploit the Flaw

Unauthenticated attackers exploit exposed nonce values in client-side JavaScript to craft malicious requests to the WordPress AJAX endpoint at /wp-admin/admin-ajax.php. These backend endpoints process membership actions without verifying origins or user authorization, leading to automatic privilege escalation and full admin access.

Experts at Cyfirma highlight that trusting user-controlled inputs without strict checks allows manipulation of authentication parameters. Successful attacks grant unrestricted control, permitting installation of malicious plugins, theme modifications for code execution, and access to sensitive user data like credentials and configs.

Potential Impacts of Exploitation

With admin privileges, hackers can establish persistent access via hidden accounts, deface sites, inject malicious scripts, or redirect visitors to phishing and malware pages. Discussions in underground forums reveal active sharing of exploit techniques and automation plans, with initial access brokers eyeing it for ransomware, SEO spam, and credential theft.

Remediation Steps

Version 5.1.3 patches the issue with enhanced validation and authorization. Site owners must update immediately, audit user accounts for unauthorized admins, invalidate suspicious sessions, and reset credentials if compromise is suspected. The flaw scores 9.8/10 on the CVSS v4.0 scale, marking it as critically severe with low exploitation complexity.

Subscribe to Our Newsletter
Subscribe to our newsletter to get our newest articles instantly!
[mc4wp_form]
Share This Article
Email Copy Link Print
Previous Article Steve Davis Fights Tears as Snooker Icons Honor John Virgo at Crucible Steve Davis Fights Tears as Snooker Icons Honor John Virgo at Crucible
Next Article Las Vegas Shooting: Gunman Barricades in STRAT Hotel After Wounding Woman Las Vegas Shooting: Gunman Barricades in STRAT Hotel After Wounding Woman

POPULAR

UK Supermarkets Hike Wages: £13 Living Wage Rule Impacts Thousands
top

UK Supermarkets Hike Wages: £13 Living Wage Rule Impacts Thousands

Elderly Man Won’t Face Charges After Shooting Intruder
top

Elderly Man Won’t Face Charges After Shooting Intruder

Rare Lemur Quadruplets Born: A Vital Boost for Endangered Species
top

Rare Lemur Quadruplets Born: A Vital Boost for Endangered Species

Rugby Star McEwen Faces Court for DUI, Suspended License
Sports

Rugby Star McEwen Faces Court for DUI, Suspended License

ESS Tech Explores Iron Flow Batteries as Lithium-Ion Alternative
business

ESS Tech Explores Iron Flow Batteries as Lithium-Ion Alternative

Trump Admits Calling Netanyahu ‘F***ing Crazy’ Over Lebanon Strikes
top

Trump Admits Calling Netanyahu ‘F***ing Crazy’ Over Lebanon Strikes

Rupert Everett: From Hedonism to Domesticity, A Life Reimagined
Entertainment

Rupert Everett: From Hedonism to Domesticity, A Life Reimagined

You Might Also Like

The Greatest USB-C Cables (2025): For iPhones, Android Telephones, Tablets, and Laptops
Technology

The Greatest USB-C Cables (2025): For iPhones, Android Telephones, Tablets, and Laptops

Extra USB-C Cables We Have ExaminedThere are such a lot of cables on the market, and loads of strong choices…

10 Min Read
The 8 Greatest WIRED-Examined Handheld Vacuums (2025)
Technology

The 8 Greatest WIRED-Examined Handheld Vacuums (2025)

Evaluate Our PicksOthers We Examined{Photograph}: Molly HigginsTineco Go Mini Cordless Hand Vacuum for $130: This light-weight vacuum is pretty easy,…

6 Min Read
Finest Reusable Water Bottles of 2025, Examined & Reviewed
Technology

Finest Reusable Water Bottles of 2025, Examined & Reviewed

Examine Prime 7 Reusable Water BottlesExtra Bottles to Think aboutCourtesy of FellowFellow Carter Carry Water Bottle for $45: Fellow's latest…

17 Min Read
Meraki Espresso Machine Evaluation: Effective Grind, Unfastened Match
Technology

Meraki Espresso Machine Evaluation: Effective Grind, Unfastened Match

Alongside grinding and dosing by weight, the steam wand likewise permits for a little bit of added management, with settings…

4 Min Read
Madisony

We cover the stories that shape the world, from breaking global headlines to the insights behind them. Our mission is simple: deliver news you can rely on, fast and fact-checked.

Recent News

UK Supermarkets Hike Wages: £13 Living Wage Rule Impacts Thousands
UK Supermarkets Hike Wages: £13 Living Wage Rule Impacts Thousands
June 4, 2026
Elderly Man Won’t Face Charges After Shooting Intruder
Elderly Man Won’t Face Charges After Shooting Intruder
June 4, 2026
Rare Lemur Quadruplets Born: A Vital Boost for Endangered Species
Rare Lemur Quadruplets Born: A Vital Boost for Endangered Species
June 4, 2026

Trending News

UK Supermarkets Hike Wages: £13 Living Wage Rule Impacts Thousands
Elderly Man Won’t Face Charges After Shooting Intruder
Rare Lemur Quadruplets Born: A Vital Boost for Endangered Species
Rugby Star McEwen Faces Court for DUI, Suspended License
ESS Tech Explores Iron Flow Batteries as Lithium-Ion Alternative
  • About Us
  • Privacy Policy
  • Terms Of Service
Reading: Update Now: 60K WordPress Sites Face Admin Hack Risk
Share

2025 © Madisony.com. All Rights Reserved.

Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?