CVE-2026-12949 (matched: wordpress)

  • Friday, 14th August, 2026
  • 10:06am

A security flaw has been found in the Wishlist Member plugin for WordPress, affecting all versions up to and including 3.34.1. This issue lets unauthenticated attackers take over any existing account on a site running the plugin, including administrator accounts, without needing to know the account’s login credentials.

The vulnerability works by letting an attacker use a target user’s ID to trick the plugin into overwriting that account’s username, password, email address, and name with values the attacker chooses. Normal emails that would alert a user to changes to their account are blocked, so the real account owner will not notice the takeover. If the attacker specifies a non-existent membership level during the attack, the target user’s existing permissions (including full administrator access) are kept, giving the attacker complete control of the entire WordPress site.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-12949

« Back