CVE-2026-6419Patch

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The WishList Member plugin for WordPress is vulnerable to Privilege Escalation via Missing Authorization in versions up to and including 3.30.1. This is due to the missing capability and nonce check in the ajax_get_screen() function. This makes it possible for authenticated attackers, with Subscriber-level access and above, to supply an arbitrary admin screen identifier via the data[url] parameter, causing the plugin to load and execute the administrative API configuration template without authorization. The rendered HTML, which contains the plugin's plaintext REST API Secret Key, is returned directly to the attacker in the AJAX JSON response. An attacker who obtains this key can authenticate to the WishList Member API, create a new membership level assigned the administrator WordPress role, and register an arbitrary administrator-level user account, resulting in complete site takeover.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 4 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 3 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 3d ago at 1 mentions (2026-05-23); latest day: 1
  • 4 total mentions across 4 days

Deep dive

Activity timeline4 mentions / 4d
00111Mentions · 2026-05-23: 1Mentions · 2026-05-25: 1Mentions · 2026-06-07: 1Mentions · 2026-06-08: 1Patch / Workaround · 2026-05-25: 1Patch / Workaround · 2026-06-07: 1Technical Details · 2026-05-23: 1Technical Details · 2026-05-25: 1Technical Details · 2026-06-07: 105-2305-2506-0706-08
Signal classification3 categories
Patch
250.0%
Disclosure
125.0%
General
125.0%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-231
Disclosure1
2026-05-251
Patch1
2026-06-071
Patch1
2026-06-081
General1
Full discourse4 posts
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    General

    CVE-2026-6419 WordPress用WishList Memberプラグイン(バージョン3.30.1まで)の脆弱性をわかりやすく解説|影響範囲と対策まとめ https://www.cybernote.click/2026/06/06/cve-2026-6419-wordpresswishlist-member3301/ #IT #Security #cybersecurity

    Post summary

    The post is a Japanese article that briefly announces CVE‑2026‑6419 affecting WordPress WishList Member up to version 3.30.1, offering a general explanation of the issue and a summary of impact and mitigation advice, but it does not provide detailed technical or exploit information.

    0000047
    209 followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    Patch

    CVE-2026-6419 WordPress用WishList Memberプラグイン(バージョン3.30.1まで)の脆弱性をわかりやすく解説|影響範囲と対策まとめ https://www.cybernote.click/2026/06/06/cve-2026-6419-wordpresswishlist-member3301/ #IT #Security #cybersecurity

    Post summary

    The post explains CVE‑2026‑6419 in the WordPress WishList Member plugin (versions ≤ 3.30.1) and outlines mitigation steps, suggesting available patches or workarounds.

    0000035
    209 followersView on X
  • NerdieNews@NewsNerdie
    Patch

    ⚠️ CVE-2026-6419 in Wishlist Member plugin lets attackers escalate privileges via 'wlm3_get_screen' AJAX action. Patch now to prevent unauthorized access and potential data leaks. #NerdieNews #CyberSecurity #Vulnerability https://t.co/UcVXx79mdt

    Post summary

    The tweet highlights CVE‑2026‑6419 in the Wishlist Member plugin, warns about privilege escalation through the wlm3_get_screen AJAX action, and urges applying the current patch to prevent unauthorized access.

    0000078
    64 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-6419 The WishList Member plugin for WordPress is vulnerable to Privilege Escalation via Missing Authorization in versions up to and including 3.30.1. This is due to the miss… https://www.cve.org/CVERecord?id=CVE-2026-6419

    Post summary

    The WishList Member plugin for WordPress is vulnerable to privilege escalation due to a missing authorization check in versions up to 3.30.1, as disclosed in CVE-2026-6419. No PoC, exploit code, or patch information is provided.

    00000162
    57.5K followersView on X

Explore more