8.8
/ 10
HIGH
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Description
The Wishlist Member plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'WishListMember3_Hooks::generate_api_key' function in all versions up to, and including, 3.30.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update the REST API Secret Key, which can be used to create a new membership level assigned the administrator WordPress role, and register an arbitrary administrator-level user account, resulting in complete site takeover.
AI Analysis
Missing capability check in Wishlist Member plugin allows authenticated attackers to update REST API Secret Key and create administrator-level user account
Basic Information
ID
CVE-2026-6898
Source
Wordfence
Published
May 23, 2026 at 04:27
Affected Product
Vendor
Wishlist Member
Product
Wishlist Member
Affected Versions
Wishlist Member Wishlist Member 0
CWE Classification
AI Assessment
AI Score
8.8 / 10
AI Severity
High
Vendor
Wishlist Member
Product
Wishlist Member
Version
3.30.1