Mehrere Schwachstellen (CVE-2026-1492, CVE-2026-1566, CVE-2026-2448, CVE-2026-2628) in Wordpress
Zusammenfassung
Eine kritische Sicherheitslücke mit CVE-2026-1492 wurde im WordPress-Plugin "User Registration & Membership" entdeckt. Durch fehlerhafte Rechteverwaltung können unauthentifizierte Angreifer Administratorkonten erstellen. Das Plugin sollte dringend auf die neueste Version aktualisiert werden, um diese Schwachstelle zu schließen.
The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to improper privilege management in all versions up to, and including, 5.1.2. This is due to the plugin accepting a user-supplied role during membership registration without properly enforcing a server-side allowlist. This makes it possible for unauthenticated attackers to create administrator accounts by supplying a role value during membership registration.
Quelle: app.opencve.io