WordPress membership plugin bug exploited to create admin accounts
2026-03-05T19:23:39Z•2b48ed2cd19574052a6dbc2bc15ece12a85d1c149e20890c12341b3c40c3c408
admin-account-creationbitwardenciscocorunacrypto-theftcybercrime-forumfbi-arrestfreescoutgoogle-threat-intelios-exploitskb5075039leakbasemail2shellpasskeysphobos-ransomwareprivilege-escalationremote-code-executionsd-wansecure-fmcus-marshalsuser-registration-membership-pluginwindows10wordpresszero-clickzero-day
What happened
Feed of BleepingComputer security news (Mar 4–5, 2026) covering multiple high‑impact incidents and disclosures: a critical vulnerability in the User Registration & Membership WordPress plugin is being exploited to create admin accounts; Google reports 90 zero‑days were exploited in 2025; a Mail2Shell zero‑click RCE in FreeScout allows unauthenticated remote code execution; Cisco flags actively exploited SD‑WAN flaws and separate maximum‑severity Secure FMC vulnerabilities that provide root access; the Coruna iOS exploit kit (23 exploits) is being used in crypto theft/espionage; FBI arrests a U
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- bleepingcomputer
- Record identifier
- 2b48ed2cd19574052a6dbc2bc15ece12a85d1c149e20890c12341b3c40c3c408
- Enrichment time
- 2026-03-05T19:23:39Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.