# CVE-2026-1492

## Summary

- **CVE ID:** CVE-2026-1492
- **Severity:** CRITICAL
- **CVSS Score:** 9.8 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H)
- **CWE:** CWE-269
- **Published:** Mar 3, 2026
- **Last Modified:** Mar 12, 2026

## Description

The User Registration & Membership – Custom Registration Form Builder, Custom Login Form, User Profile, Content Restriction & Membership Plugin plugin for WordPress is vulnerable to improper privilege management in all versions up to, and including, 5.1.2. This is due to the plugin accepting a user-supplied role during membership registration without properly enforcing a server-side allowlist. This makes it possible for unauthenticated attackers to create administrator accounts by supplying a role value during membership registration.

## Affected Products

- wpeverest — User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder (*)

## References

- [CNA](https://www.wordfence.com/threat-intel/vulnerabilities/id/7e9fec92-f471-4ce9-9138-1c58ad658da2?source=cve)
- [CNA](https://plugins.trac.wordpress.org/changeset/3469042/user-registration)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 24.23%
- **EPSS Percentile:** 97.7

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._