A security flaw has been found in the Wishlist Member plugin for WordPress, affecting all versions up to and including 3.34.1. This flaw allows people who do not have any existing login access to your site to take over any existing WordPress account on your site, including administrator accounts that have full control over your site’s content and settings.
When exploited, these attackers can change the target account’s username, password, email address, first name, and last name to values of their choosing. The site will not send the standard password and email change notification emails that WordPress normally sends to account owners when these changes are made, so the takeover can occur without you noticing right away.
If the attacker takes over an administrator account, they will keep that account’s full administrator permissions, giving them complete control over your site and all its data.
Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-12949