By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
MadisonyMadisony
Notification Show More
Font ResizerAa
  • Home
  • National & World
  • Politics
  • Investigative Reports
  • Education
  • Health
  • Entertainment
  • Technology
  • Sports
  • Money
  • Pets & Animals
Reading: Update Now: 60K WordPress Sites Face Admin Hack Risk
Share
Font ResizerAa
MadisonyMadisony
Search
  • Home
  • National & World
  • Politics
  • Investigative Reports
  • Education
  • Health
  • Entertainment
  • Technology
  • Sports
  • Money
  • Pets & Animals
Have an existing account? Sign In
Follow US
2025 © Madisony.com. All Rights Reserved.
Technology

Update Now: 60K WordPress Sites Face Admin Hack Risk

Madisony
Last updated: April 18, 2026 9:15 pm
Madisony
Share
Update Now: 60K WordPress Sites Face Admin Hack Risk
SHARE

A critical security vulnerability in the User Registration & Membership plugin threatens over 60,000 WordPress websites, enabling hackers to create hidden admin accounts without authentication. Tracked as CVE-2026-1492, the flaw affects versions up to 5.1.2 and stems from inadequate server-side validation and weak authorization in the membership workflow.

Contents
How Attackers Exploit the FlawPotential Impacts of ExploitationRemediation Steps

How Attackers Exploit the Flaw

Unauthenticated attackers exploit exposed nonce values in client-side JavaScript to craft malicious requests to the WordPress AJAX endpoint at /wp-admin/admin-ajax.php. These backend endpoints process membership actions without verifying origins or user authorization, leading to automatic privilege escalation and full admin access.

Experts at Cyfirma highlight that trusting user-controlled inputs without strict checks allows manipulation of authentication parameters. Successful attacks grant unrestricted control, permitting installation of malicious plugins, theme modifications for code execution, and access to sensitive user data like credentials and configs.

Potential Impacts of Exploitation

With admin privileges, hackers can establish persistent access via hidden accounts, deface sites, inject malicious scripts, or redirect visitors to phishing and malware pages. Discussions in underground forums reveal active sharing of exploit techniques and automation plans, with initial access brokers eyeing it for ransomware, SEO spam, and credential theft.

Remediation Steps

Version 5.1.3 patches the issue with enhanced validation and authorization. Site owners must update immediately, audit user accounts for unauthorized admins, invalidate suspicious sessions, and reset credentials if compromise is suspected. The flaw scores 9.8/10 on the CVSS v4.0 scale, marking it as critically severe with low exploitation complexity.

Subscribe to Our Newsletter
Subscribe to our newsletter to get our newest articles instantly!
[mc4wp_form]
Share This Article
Email Copy Link Print
Previous Article Steve Davis Fights Tears as Snooker Icons Honor John Virgo at Crucible Steve Davis Fights Tears as Snooker Icons Honor John Virgo at Crucible
Next Article Las Vegas Shooting: Gunman Barricades in STRAT Hotel After Wounding Woman Las Vegas Shooting: Gunman Barricades in STRAT Hotel After Wounding Woman

POPULAR

Las Vegas Shooting: Gunman Barricades in STRAT Hotel After Wounding Woman
world

Las Vegas Shooting: Gunman Barricades in STRAT Hotel After Wounding Woman

Update Now: 60K WordPress Sites Face Admin Hack Risk
Technology

Update Now: 60K WordPress Sites Face Admin Hack Risk

Steve Davis Fights Tears as Snooker Icons Honor John Virgo at Crucible
top

Steve Davis Fights Tears as Snooker Icons Honor John Virgo at Crucible

Grab 12.5% NLY and 11.5% PDO Yields in Market Dip
business

Grab 12.5% NLY and 11.5% PDO Yields in Market Dip

Leno’s Heroics Deny Brentford in Tense Goalless Derby Draw
Sports

Leno’s Heroics Deny Brentford in Tense Goalless Derby Draw

France Ditches Windows for Linux on 2.5M Gov PCs by 2026
Technology

France Ditches Windows for Linux on 2.5M Gov PCs by 2026

Tulisa Reveals Bell’s Palsy Attack, Cancels Egg Retrieval in Health Update
Entertainment

Tulisa Reveals Bell’s Palsy Attack, Cancels Egg Retrieval in Health Update

You Might Also Like

Important Gear for an Emergency Equipment—for Vehicles or Go-Baggage
Technology

Important Gear for an Emergency Equipment—for Vehicles or Go-Baggage

You by no means know when you are going to should bug out on brief discover. The politics of the…

5 Min Read
Republicans Claimed Biden Censored YouTube. 20 Staff Appear to Say In any other case
Technology

Republicans Claimed Biden Censored YouTube. 20 Staff Appear to Say In any other case

In a letter to a Home committee final month, authorized counsel for Alphabet, YouTube’s guardian firm, claimed that president Joe…

3 Min Read
YouTube Thinks AI Is Its Subsequent Massive Bang
Technology

YouTube Thinks AI Is Its Subsequent Massive Bang

Google discovered early on that video can be a fantastic addition to its search enterprise, so in 2005 it launched…

6 Min Read
OpenAI Launches GPT-5.2 as It Navigates ‘Code Pink’
Technology

OpenAI Launches GPT-5.2 as It Navigates ‘Code Pink’

OpenAI has launched GPT-5.2, its smartest synthetic intelligence mannequin but, with efficiency features throughout writing, coding, and reasoning benchmarks. The…

3 Min Read
Madisony

We cover the stories that shape the world, from breaking global headlines to the insights behind them. Our mission is simple: deliver news you can rely on, fast and fact-checked.

Recent News

Las Vegas Shooting: Gunman Barricades in STRAT Hotel After Wounding Woman
Las Vegas Shooting: Gunman Barricades in STRAT Hotel After Wounding Woman
April 18, 2026
Update Now: 60K WordPress Sites Face Admin Hack Risk
Update Now: 60K WordPress Sites Face Admin Hack Risk
April 18, 2026
Steve Davis Fights Tears as Snooker Icons Honor John Virgo at Crucible
Steve Davis Fights Tears as Snooker Icons Honor John Virgo at Crucible
April 18, 2026

Trending News

Las Vegas Shooting: Gunman Barricades in STRAT Hotel After Wounding Woman
Update Now: 60K WordPress Sites Face Admin Hack Risk
Steve Davis Fights Tears as Snooker Icons Honor John Virgo at Crucible
Grab 12.5% NLY and 11.5% PDO Yields in Market Dip
Leno’s Heroics Deny Brentford in Tense Goalless Derby Draw
  • About Us
  • Privacy Policy
  • Terms Of Service
Reading: Update Now: 60K WordPress Sites Face Admin Hack Risk
Share

2025 © Madisony.com. All Rights Reserved.

Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?