Account Takeover Vulnerability in Wishlist Member Plugin for WordPress
CVE-2026-12949

9.8CRITICAL

Key Information:

Vendor

WordPress

Vendor
CVE Published:
14 August 2026

What is CVE-2026-12949?

The Wishlist Member plugin for WordPress is susceptible to account takeover due to inadequate verification of data authenticity in its registration process. This vulnerability allows unauthenticated attackers to take control of existing WordPress accounts, including those of administrators, by manipulating specific POST parameters, thereby overriding user details such as username and password. The wpm_register() function fails to adequately validate user IDs in the registration cookie, permitting malicious actors to exploit the system and escalate their privileges without detection. Additionally, notifications related to changes are suppressed, further obscuring the attacker's actions.

Affected Version(s)

Wishlist Member 0 <= 3.34.1

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

bashu
.