CriticalVulnerabilities

WordPress Plugin Bug Lets Hackers Create Admin Accounts

Emanuel DE ALMEIDA 5 March 2026 2 min read 11 views 0 Comments

Last updated 8 March 2026

WordPress admin dashboard displaying user management interface in dark cybersecurity setting

Critical flaw in User Registration plugin affects 60,000+ WordPress sites, enabling unauthorized admin account creation.

Key Takeaways

WordPress Plugin Flaw Enables Admin Account Takeovers

Hackers exploited a critical vulnerability in the User Registration & Membership plugin on March 5th. The flaw affects over 60,000 WordPress installations worldwide.

The bug allows attackers to bypass authentication controls and create administrator accounts without authorization. Security researchers confirmed active exploitation attempts targeting vulnerable sites.

According to The Hacker News, the vulnerability stems from improper input validation in the plugin's user registration process.

60,000+ WordPress Sites at Risk

WordPress sites running the User Registration & Membership plugin face immediate risk. The plugin maintains over 60,000 active installations across various industries.

Attackers can exploit the flaw remotely without user interaction. No special privileges are required to execute the attack, making it particularly dangerous for unpatched sites.

Small businesses and personal websites represent the majority of affected installations, though enterprise WordPress deployments also use the plugin.

Plugin Update Addresses Security Gap

The plugin developers released a security update addressing the authentication bypass flaw. Site administrators must update to the latest version immediately.

WordPress site owners can check their plugin version through the admin dashboard. The vulnerable versions allow unauthorized admin account creation through manipulated registration requests.

Security teams recommend reviewing user accounts created recently and implementing additional access controls while updating affected systems.

About the Author

Emanuel DE ALMEIDA

Emanuel DE ALMEIDA

Senior IT Journalist & Cloud Architect

Microsoft MCSA-certified Cloud Architect | Fortinet-focused. I modernize cloud, hybrid & on-prem infrastructure for reliability, security, performance and cost control - sharing field-tested ops & troubleshooting.

#wordpress#authentication-bypass#plugin-vulnerability

Frequently Asked Questions

How do I check if my WordPress site uses this plugin?
Log into your WordPress admin dashboard and navigate to Plugins > Installed Plugins. Look for 'User Registration & Membership' in the list. If present, check the version number and update immediately.
What can hackers do with admin access to my WordPress site?
Admin access allows complete site control including installing malicious plugins, stealing data, defacing content, and using your site for further attacks. Hackers can also access sensitive customer information stored in the database.
How can I tell if my site was already compromised?
Check your user accounts for any administrators you didn't create, especially those created recently. Review recent plugin installations and file modifications. Consider running a security scan to detect malicious code.

Discussion

Share your thoughts and insights

You must be logged in to comment.

Loading comments...