By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
MadisonyMadisony
Notification Show More
Font ResizerAa
  • Home
  • National & World
  • Politics
  • Investigative Reports
  • Education
  • Health
  • Entertainment
  • Technology
  • Sports
  • Money
  • Pets & Animals
Reading: Update Now: 60K WordPress Sites Face Admin Hack Risk
Share
Font ResizerAa
MadisonyMadisony
Search
  • Home
  • National & World
  • Politics
  • Investigative Reports
  • Education
  • Health
  • Entertainment
  • Technology
  • Sports
  • Money
  • Pets & Animals
Have an existing account? Sign In
Follow US
2025 © Madisony.com. All Rights Reserved.
Technology

Update Now: 60K WordPress Sites Face Admin Hack Risk

Madisony
Last updated: April 18, 2026 9:15 pm
Madisony
Share
Update Now: 60K WordPress Sites Face Admin Hack Risk
SHARE

A critical security vulnerability in the User Registration & Membership plugin threatens over 60,000 WordPress websites, enabling hackers to create hidden admin accounts without authentication. Tracked as CVE-2026-1492, the flaw affects versions up to 5.1.2 and stems from inadequate server-side validation and weak authorization in the membership workflow.

Contents
How Attackers Exploit the FlawPotential Impacts of ExploitationRemediation Steps

How Attackers Exploit the Flaw

Unauthenticated attackers exploit exposed nonce values in client-side JavaScript to craft malicious requests to the WordPress AJAX endpoint at /wp-admin/admin-ajax.php. These backend endpoints process membership actions without verifying origins or user authorization, leading to automatic privilege escalation and full admin access.

Experts at Cyfirma highlight that trusting user-controlled inputs without strict checks allows manipulation of authentication parameters. Successful attacks grant unrestricted control, permitting installation of malicious plugins, theme modifications for code execution, and access to sensitive user data like credentials and configs.

Potential Impacts of Exploitation

With admin privileges, hackers can establish persistent access via hidden accounts, deface sites, inject malicious scripts, or redirect visitors to phishing and malware pages. Discussions in underground forums reveal active sharing of exploit techniques and automation plans, with initial access brokers eyeing it for ransomware, SEO spam, and credential theft.

Remediation Steps

Version 5.1.3 patches the issue with enhanced validation and authorization. Site owners must update immediately, audit user accounts for unauthorized admins, invalidate suspicious sessions, and reset credentials if compromise is suspected. The flaw scores 9.8/10 on the CVSS v4.0 scale, marking it as critically severe with low exploitation complexity.

Subscribe to Our Newsletter
Subscribe to our newsletter to get our newest articles instantly!
[mc4wp_form]
Share This Article
Email Copy Link Print
Previous Article Steve Davis Fights Tears as Snooker Icons Honor John Virgo at Crucible Steve Davis Fights Tears as Snooker Icons Honor John Virgo at Crucible
Next Article Las Vegas Shooting: Gunman Barricades in STRAT Hotel After Wounding Woman Las Vegas Shooting: Gunman Barricades in STRAT Hotel After Wounding Woman

POPULAR

Elderly Man Won’t Face Charges After Shooting Intruder
top

Elderly Man Won’t Face Charges After Shooting Intruder

Rare Lemur Quadruplets Born: A Vital Boost for Endangered Species
top

Rare Lemur Quadruplets Born: A Vital Boost for Endangered Species

Rugby Star McEwen Faces Court for DUI, Suspended License
Sports

Rugby Star McEwen Faces Court for DUI, Suspended License

ESS Tech Explores Iron Flow Batteries as Lithium-Ion Alternative
business

ESS Tech Explores Iron Flow Batteries as Lithium-Ion Alternative

Trump Admits Calling Netanyahu ‘F***ing Crazy’ Over Lebanon Strikes
top

Trump Admits Calling Netanyahu ‘F***ing Crazy’ Over Lebanon Strikes

Rupert Everett: From Hedonism to Domesticity, A Life Reimagined
Entertainment

Rupert Everett: From Hedonism to Domesticity, A Life Reimagined

Cancer & Endometriosis Drug Withdrawal Sparks Patient Outrage
world

Cancer & Endometriosis Drug Withdrawal Sparks Patient Outrage

You Might Also Like

PS5 Slow Downloads? 5GHz Wi-Fi Switch Cuts 6-Hour Wait to 90 Minutes
Technology

PS5 Slow Downloads? 5GHz Wi-Fi Switch Cuts 6-Hour Wait to 90 Minutes

Gamers frequently face long wait times for PS5 game downloads, even on decent home networks. A recent attempt to download…

2 Min Read
Finest Microsoft Floor Laptop computer (2026): Which Mannequin to Purchase or Keep away from
Technology

Finest Microsoft Floor Laptop computer (2026): Which Mannequin to Purchase or Keep away from

However greater than something, the polish of the laptop computer's design and the standard of its parts are what make…

5 Min Read
The Girl from Plainville: Chilling True Crime Drama Free on Channel 4
businessEducationEntertainmentHealthPoliticsSportsTechnologytopworld

The Girl from Plainville: Chilling True Crime Drama Free on Channel 4

A compelling drama series exploring a devastating real-life tragedy is now available to stream for free on Channel 4. 'The…

4 Min Read
Google PM open-sources All the time On Reminiscence Agent, ditching vector databases for LLM-driven persistent reminiscence
Technology

Google PM open-sources All the time On Reminiscence Agent, ditching vector databases for LLM-driven persistent reminiscence

Google senior AI product supervisor Shubham Saboo has turned one of many thorniest issues in agent design into an open-source…

10 Min Read
Madisony

We cover the stories that shape the world, from breaking global headlines to the insights behind them. Our mission is simple: deliver news you can rely on, fast and fact-checked.

Recent News

Elderly Man Won’t Face Charges After Shooting Intruder
Elderly Man Won’t Face Charges After Shooting Intruder
June 4, 2026
Rare Lemur Quadruplets Born: A Vital Boost for Endangered Species
Rare Lemur Quadruplets Born: A Vital Boost for Endangered Species
June 4, 2026
Rugby Star McEwen Faces Court for DUI, Suspended License
Rugby Star McEwen Faces Court for DUI, Suspended License
June 4, 2026

Trending News

Elderly Man Won’t Face Charges After Shooting Intruder
Rare Lemur Quadruplets Born: A Vital Boost for Endangered Species
Rugby Star McEwen Faces Court for DUI, Suspended License
ESS Tech Explores Iron Flow Batteries as Lithium-Ion Alternative
Trump Admits Calling Netanyahu ‘F***ing Crazy’ Over Lebanon Strikes
  • About Us
  • Privacy Policy
  • Terms Of Service
Reading: Update Now: 60K WordPress Sites Face Admin Hack Risk
Share

2025 © Madisony.com. All Rights Reserved.

Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?