Account Takeover Vulnerability in Wishlist Member Plugin for WordPress
CVE-2026-12949
9.8CRITICAL
What is CVE-2026-12949?
The Wishlist Member plugin for WordPress is susceptible to account takeover due to inadequate verification of data authenticity in its registration process. This vulnerability allows unauthenticated attackers to take control of existing WordPress accounts, including those of administrators, by manipulating specific POST parameters, thereby overriding user details such as username and password. The wpm_register() function fails to adequately validate user IDs in the registration cookie, permitting malicious actors to exploit the system and escalate their privileges without detection. Additionally, notifications related to changes are suppressed, further obscuring the attacker's actions.
Affected Version(s)
Wishlist Member 0 <= 3.34.1