8.8
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Description
The Wishlist Member plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'WishListMember\Features\Team_Accounts::save_settings' function in all versions up to, and including, 3.30.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary plugin options, includes the REST API Secret Key, which can be used to create a new membership level assigned the administrator WordPress role, and register an arbitrary administrator-level user account, resulting in complete site takeover.
AI Analysis
Missing capability check allows authenticated attackers to update arbitrary plugin options, potentially leading to site takeover.
Basic Information
ID
CVE-2026-6897
Source
Wordfence
Published
May 23, 2026 at 04:27
Affected Product
Vendor
Wishlist Member
Product
Wishlist Member
Affected Versions
Wishlist Member Wishlist Member 0
CWE Classification
AI Assessment
AI Score
8.8 / 10
AI Severity
High
Vendor
Wishlist Member
Product
Wishlist Member
Version
3.30.1