CVE-2026-6895

The WishList Member plugin for WordPress is vulnerable to Missing Authorization leading to Sensitive Information Disclosure and Privilege Escalation in versions up to and including 3.30.1. This is due to the missing capability checks in the 'export_settings' function. This function returns the REST API Secret Key to the attacker in the AJAX JSON response. An attacker who obtains this key can authenticate to the WishList Member API, create a new membership level assigned the administrator WordPress role, and register an arbitrary administrator-level user account, resulting in complete site takeover.
Configurations

No configuration.

History

23 Jul 2026, 11:10

Type Values Removed Values Added
Summary
  • (es) El plugin WishList Member para WordPress es vulnerable a una Falta de Autorización que conduce a la Revelación de Información Sensible y a la Escalada de Privilegios en versiones hasta la 3.30.1 inclusive. Esto se debe a la falta de comprobaciones de capacidad en la función 'export_settings'. Esta función devuelve la Clave Secreta de la API REST al atacante en la respuesta JSON AJAX. Un atacante que obtiene esta clave puede autenticarse en la API de WishList Member, crear un nuevo nivel de membresía al que se le asigne el rol de administrador de WordPress y registrar una cuenta de usuario arbitraria con nivel de administrador, lo que resulta en una toma de control completa del sitio.

23 May 2026, 05:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-23 05:16

Updated : 2026-07-23 11:10


NVD link : CVE-2026-6895

Mitre link : CVE-2026-6895

CVE.ORG link : CVE-2026-6895


JSON object : View

Products Affected

No product.

CWE
CWE-269

Improper Privilege Management