Unauthorized Data Modification in Wishlist Member Plugin for WordPress
CVE-2026-6897
8.8HIGH
What is CVE-2026-6897?
The Wishlist Member plugin for WordPress has a weakness that enables unauthorized data changes due to a lack of necessary capability checks in the 'WishListMember\Features\Team_Accounts::save_settings' function. This vulnerability affects all versions up to and including 3.30.1. Authenticated attackers with Subscriber-level access or higher can manipulate plugin settings, including the REST API Secret Key. This compromise allows them to create a new membership level with administrative rights and register new administrator accounts, leading to potential complete control over the affected WordPress site.
Affected Version(s)
Wishlist Member 0 <= 3.30.1