CVE-2026-6897

The Wishlist Member plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'WishListMember\Features\Team_Accounts::save_settings' function in all versions up to, and including, 3.30.1. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update arbitrary plugin options, includes the REST API Secret Key, which can be used to create a new membership level assigned the administrator WordPress role, and register an arbitrary administrator-level user account, resulting in complete site takeover.
Configurations

No configuration.

History

23 Jul 2026, 11:10

Type Values Removed Values Added
Summary
  • (es) El plugin Wishlist Member para WordPress es vulnerable a la modificación no autorizada de datos debido a una comprobación de capacidad faltante en la función 'WishListMember\Features\Team_Accounts::save_settings' en todas las versiones hasta la 3.30.1, inclusive. Esto hace posible que atacantes autenticados, con acceso de nivel Suscriptor y superior, actualicen opciones arbitrarias del plugin, incluyendo la Clave Secreta de la API REST, que puede ser utilizada para crear un nuevo nivel de membresía asignado el rol de administrador de WordPress, y registrar una cuenta de usuario arbitraria de nivel administrador, resultando en una toma de control completa del sitio.

23 May 2026, 05:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-05-23 05:16

Updated : 2026-07-23 11:10


NVD link : CVE-2026-6897

Mitre link : CVE-2026-6897

CVE.ORG link : CVE-2026-6897


JSON object : View

Products Affected

No product.

CWE
CWE-269

Improper Privilege Management