CVE-2026-12949Patch

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The Wishlist Member plugin for WordPress is vulnerable to Account Takeover via Insufficient Verification of Data Authenticity in versions up to and including 3.34.1. This is due to the wpm_register() function validating the registration cookie only against the GET reg parameter while accepting the POST mergewith and POST wpm_id parameters without verifying that the mergewith user ID references a temporary or incomplete registrant that is bound to the current registration transaction. This makes it possible for unauthenticated attackers to take over any existing WordPress account — including administrator accounts — by supplying an arbitrary user's numeric ID as the mergewith value, which causes wp_update_user() to overwrite the target account's username (additionally written via a direct $wpdb UPDATE), password, email address, first name, and last name with attacker-controlled values, while WordPress password and email change notification emails are explicitly suppressed. When wpm_id references a non-existent membership level, no role key is added to the update payload, causing wp_update_user() to preserve the target user's existing role — including administrator — making full privilege escalation a direct consequence of the takeover.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-640

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 4 signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 3 mentions (2026-08-14); latest day: 1
  • 4 total mentions across 2 days

Deep dive

Activity timeline4 mentions / 2d
01223Mentions · 2026-08-14: 3Mentions · 2026-08-15: 1Patch / Workaround · 2026-08-14: 2Patch / Workaround · 2026-08-15: 1Technical Details · 2026-08-14: 3Technical Details · 2026-08-15: 108-1408-15
Signal classification2 categories
Patch
375.0%
Disclosure
125.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-08-143
Disclosure1Patch2
2026-08-151
Patch1
Full discourse4 posts
  • Hugo | DevOps | Cybersecurity 🇱🇻@HugoValters
    Patch

    CVE-2026-12949 - Critical Account Takeover in Wishlist Member WordPress plugin. Insufficient verification allows attacker to merge accounts. CVSS 9.8. Unpatched. Update immediately. #CVE #WordPress #infosec https://www.valtersit.com/cve/CVE-2026-12949 #CVE #infosec #SysAdmin #cybersecurity #Linux #infosec #devsecops #devops #developer #sysadmin #100daysofcode #git #github #gitlab #redteam #blueteam #ethicalhacker #ethicalhacking #cybersecurityawareness #cybersecurity #cybersecuritynews #cybersecuritytips #python #hacker #linux #kali #ubuntu #debian #ukraine #spain #ireland #unitedkingdom #canada #finland #estonia #lithuania #ireland #hungary #denmark #norway #malta

    Post summary

    CVE‑2026‑12949 is a critical account‑takeover flaw in the Wishlist Member WordPress plugin that remains unpatched; users are urged to update immediately to mitigate the vulnerability.

    0000057
    1.0K followersView on X
  • ADK Cyber@ADKCyber
    Patch

    CVE-2026-12949 (CVSS 9.8): Wishlist Member WordPress plugin vulnerable to account takeover in versions up to 3.34.1. Update immediately if in use. via NVD Recent High CVSS #CyberSecurity #InfoSec #Vulnerability https://t.co/EyftduJ5DB

    Post summary

    The tweet highlights CVE-2026-12949, a high‑severity account takeover flaw in Wishlist Member WordPress plugin (v3.34.1 and earlier) and urges users to update immediately.

    0000041
    92 followersView on X
  • ThreatAft@ThreatAft
    Patch

    🚨 CVE-2026-12949 | CVSS 9.8 Critical Wishlist Member ≤3.34.1 allows unauthenticated account takeover—including admin accounts. 🔴 Fixed in 3.34.2 🛡️ Update now, audit accounts/logs & enforce MFA. 🔗 https://threataft.com/articles/wishlist-member-auth-bypass-account-takeover-cve-2026-12949?utm_source=twitter&utm_medium=social&utm_campaign=share #CyberSecurity #WordPress #CVE #InfoSec https://t.co/plqiFdJ1Cz

    Post summary

    The tweet announces CVE‑2026‑12949, describes its critical account takeover flaw in Wishlist Member up to 3.34.1, and urges users to patch to 3.34.2 or later.

    0000053
    36 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-12949 The Wishlist Member plugin for WordPress is vulnerable to Account Takeover via Insufficient Verification of Data Authenticity in versions up to and including 3.34.1. … https://www.cve.org/CVERecord?id=CVE-2026-12949

    Post summary

    A CVE-2026-12949 vulnerability in the Wishlist Member WordPress plugin permits account takeover due to insufficient data authenticity verification, but no exploitable PoC, active exploitation, or patch is referenced.

    000001.3K
    57.9K followersView on X

Explore more