By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
MadisonyMadisony
Notification Show More
Font ResizerAa
  • Home
  • National & World
  • Politics
  • Investigative Reports
  • Education
  • Health
  • Entertainment
  • Technology
  • Sports
  • Money
  • Pets & Animals
Reading: Update Now: 60K WordPress Sites Face Admin Hack Risk
Share
Font ResizerAa
MadisonyMadisony
Search
  • Home
  • National & World
  • Politics
  • Investigative Reports
  • Education
  • Health
  • Entertainment
  • Technology
  • Sports
  • Money
  • Pets & Animals
Have an existing account? Sign In
Follow US
2025 © Madisony.com. All Rights Reserved.
Technology

Update Now: 60K WordPress Sites Face Admin Hack Risk

Madisony
Last updated: April 18, 2026 9:15 pm
Madisony
Share
Update Now: 60K WordPress Sites Face Admin Hack Risk
SHARE

A critical security vulnerability in the User Registration & Membership plugin threatens over 60,000 WordPress websites, enabling hackers to create hidden admin accounts without authentication. Tracked as CVE-2026-1492, the flaw affects versions up to 5.1.2 and stems from inadequate server-side validation and weak authorization in the membership workflow.

Contents
How Attackers Exploit the FlawPotential Impacts of ExploitationRemediation Steps

How Attackers Exploit the Flaw

Unauthenticated attackers exploit exposed nonce values in client-side JavaScript to craft malicious requests to the WordPress AJAX endpoint at /wp-admin/admin-ajax.php. These backend endpoints process membership actions without verifying origins or user authorization, leading to automatic privilege escalation and full admin access.

Experts at Cyfirma highlight that trusting user-controlled inputs without strict checks allows manipulation of authentication parameters. Successful attacks grant unrestricted control, permitting installation of malicious plugins, theme modifications for code execution, and access to sensitive user data like credentials and configs.

Potential Impacts of Exploitation

With admin privileges, hackers can establish persistent access via hidden accounts, deface sites, inject malicious scripts, or redirect visitors to phishing and malware pages. Discussions in underground forums reveal active sharing of exploit techniques and automation plans, with initial access brokers eyeing it for ransomware, SEO spam, and credential theft.

Remediation Steps

Version 5.1.3 patches the issue with enhanced validation and authorization. Site owners must update immediately, audit user accounts for unauthorized admins, invalidate suspicious sessions, and reset credentials if compromise is suspected. The flaw scores 9.8/10 on the CVSS v4.0 scale, marking it as critically severe with low exploitation complexity.

Subscribe to Our Newsletter
Subscribe to our newsletter to get our newest articles instantly!
[mc4wp_form]
Share This Article
Email Copy Link Print
Previous Article Steve Davis Fights Tears as Snooker Icons Honor John Virgo at Crucible Steve Davis Fights Tears as Snooker Icons Honor John Virgo at Crucible
Next Article Las Vegas Shooting: Gunman Barricades in STRAT Hotel After Wounding Woman Las Vegas Shooting: Gunman Barricades in STRAT Hotel After Wounding Woman

POPULAR

Rob Parker Blasts ‘Coward’ Mike Vrabel for Ducking Media After Russini Exit
top

Rob Parker Blasts ‘Coward’ Mike Vrabel for Ducking Media After Russini Exit

Las Vegas Shooting: Gunman Barricades in STRAT Hotel After Wounding Woman
world

Las Vegas Shooting: Gunman Barricades in STRAT Hotel After Wounding Woman

Update Now: 60K WordPress Sites Face Admin Hack Risk
Technology

Update Now: 60K WordPress Sites Face Admin Hack Risk

Steve Davis Fights Tears as Snooker Icons Honor John Virgo at Crucible
top

Steve Davis Fights Tears as Snooker Icons Honor John Virgo at Crucible

Grab 12.5% NLY and 11.5% PDO Yields in Market Dip
business

Grab 12.5% NLY and 11.5% PDO Yields in Market Dip

Leno’s Heroics Deny Brentford in Tense Goalless Derby Draw
Sports

Leno’s Heroics Deny Brentford in Tense Goalless Derby Draw

France Ditches Windows for Linux on 2.5M Gov PCs by 2026
Technology

France Ditches Windows for Linux on 2.5M Gov PCs by 2026

You Might Also Like

The instructor is the brand new engineer: Contained in the rise of AI enablement and PromptOps
Technology

The instructor is the brand new engineer: Contained in the rise of AI enablement and PromptOps

As extra corporations shortly start utilizing gen AI, it’s necessary to keep away from an enormous mistake that might affect…

10 Min Read
‘We Ain’t Seen Nothing But’—Trump’s Mass Deportations Will Solely Develop From Right here
Technology

‘We Ain’t Seen Nothing But’—Trump’s Mass Deportations Will Solely Develop From Right here

When Donald Trump received a second time period as US president a 12 months in the past, members of violent…

4 Min Read
OpenAI returns to open supply roots with new fashions gpt-oss-120b and gpt-oss-20b 
Technology

OpenAI returns to open supply roots with new fashions gpt-oss-120b and gpt-oss-20b 

Need smarter insights in your inbox? Join our weekly newsletters to get solely what issues to enterprise AI, information, and…

25 Min Read
Top 3 UK PayPal Casinos for Fast & Secure Gaming in 2026
businessEducationEntertainmentHealthPoliticsSportsTechnologytopworld

Top 3 UK PayPal Casinos for Fast & Secure Gaming in 2026

Why Payment Methods Matter in Online GamingModern players demand instant fund access, ironclad security, and seamless transactions across all devices.…

3 Min Read
Madisony

We cover the stories that shape the world, from breaking global headlines to the insights behind them. Our mission is simple: deliver news you can rely on, fast and fact-checked.

Recent News

Rob Parker Blasts ‘Coward’ Mike Vrabel for Ducking Media After Russini Exit
Rob Parker Blasts ‘Coward’ Mike Vrabel for Ducking Media After Russini Exit
April 18, 2026
Las Vegas Shooting: Gunman Barricades in STRAT Hotel After Wounding Woman
Las Vegas Shooting: Gunman Barricades in STRAT Hotel After Wounding Woman
April 18, 2026
Update Now: 60K WordPress Sites Face Admin Hack Risk
Update Now: 60K WordPress Sites Face Admin Hack Risk
April 18, 2026

Trending News

Rob Parker Blasts ‘Coward’ Mike Vrabel for Ducking Media After Russini Exit
Las Vegas Shooting: Gunman Barricades in STRAT Hotel After Wounding Woman
Update Now: 60K WordPress Sites Face Admin Hack Risk
Steve Davis Fights Tears as Snooker Icons Honor John Virgo at Crucible
Grab 12.5% NLY and 11.5% PDO Yields in Market Dip
  • About Us
  • Privacy Policy
  • Terms Of Service
Reading: Update Now: 60K WordPress Sites Face Admin Hack Risk
Share

2025 © Madisony.com. All Rights Reserved.

Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?