← WordPress Vulnerabilities
WordPress security by component

WishList Member

WishList Member adds membership management features for restricting content, organizing members, and handling access levels.

WishList Member (wishlist-member) is a WordPress plugin with 6 published CVE records in this archive. The latest tracked vulnerability was published Aug 14, 2026; the highest published CVSS base score is 9.8.

Plugin slug: wishlist-member

CVE-2026-12949: WishList Member registration permits unauthenticated administrator takeover

WishList Member through 3.34.1 permits unauthenticated account takeover in wpm_register(). The registration flow validates its cookie only against the reg transaction value, but accepts separate mergewith and wpm_id POST values without binding the target account to that transaction. An attacker can select an existing numeric user ID and cause wp_update_user() plus a direct database update to replace that account's username, password, email and name. Selecting a nonexistent membership level avoids changing the existing WordPress role, allowing an administrator account to remain an administrator after its credentials are replaced.

PublishedAug 14, 2026
Safe version guidanceSee mitigation notes
Published vulnerabilities for wishlist-member
Safe version
Aug 14, 2026 CVE-2026-12949
WishList Member registration permits unauthenticated administrator takeover
WishList Member through 3.34.1 permits unauthenticated account takeover in wpm_register(). The registration flow validates its cookie only against the reg transaction value, but accepts separate mergewith and wpm_id POST values without binding the target account to that transaction. An attacker can select an existing numeric user ID and cause wp_update_user() plus a direct database update to replace that account's username, password, email and name. Selecting a nonexistent membership level avoids changing the existing WordPress role, allowing an administrator account to remain an administrator after its credentials are replaced.
See mitigation notes
CVE9.8
NVDPending
Jul 23, 2026 CVE-2026-57384
WishList Member X: Cross-site scripting
WishList Member X is affected by cross-site scripting. Exploitation requires an authenticated subscriber account. Injected script can execute in the affected site's origin when the vulnerable output is viewed. The published affected range is n/a through 3.32.0.
3.33.0
CVE6.5
NVDPending
May 23, 2026 CVE-2026-6898
Wishlist Member: A security weakness
Wishlist Member is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 3.30.1.
See mitigation notes
CVE8.8
NVDPending
May 23, 2026 CVE-2026-6897
Wishlist Member: A security weakness
Wishlist Member is affected by a security weakness. Exploitation requires an authenticated subscriber account. The resulting impact depends on how the affected component exposes the vulnerable operation. The published affected range is <= 3.30.1.
See mitigation notes
CVE8.8
NVDPending
May 23, 2026 CVE-2026-6895
Wishlist Member: Privilege escalation or authentication bypass
Wishlist Member is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess. The published affected range is <= 3.30.1.
See mitigation notes
CVE8.8
NVDPending
May 23, 2026 CVE-2026-6419
Wishlist Member: Privilege escalation or authentication bypass
Wishlist Member is affected by privilege escalation or authentication bypass. Exploitation requires an authenticated subscriber account. A successful request can grant permissions or access that the caller should not possess. The published affected range is <= 3.30.1.
See mitigation notes
CVE8.8
NVDPending