CVE-2026-6895Disclosure

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The WishList Member plugin for WordPress is vulnerable to Missing Authorization leading to Sensitive Information Disclosure and Privilege Escalation in versions up to and including 3.30.1. This is due to the missing capability checks in the 'export_settings' function. This function returns the REST API Secret Key to the attacker in the AJAX JSON response. An attacker who obtains this key can authenticate to the WishList Member API, create a new membership level assigned the administrator WordPress role, and register an arbitrary administrator-level user account, resulting in complete site takeover.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-269

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 3 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 2d ago at 1 mentions (2026-05-23); latest day: 1
  • 3 total mentions across 3 days

Deep dive

Activity timeline3 mentions / 3d
00111Mentions · 2026-05-23: 1Mentions · 2026-06-07: 1Mentions · 2026-06-09: 1Patch / Workaround · 2026-06-07: 1Patch / Workaround · 2026-06-09: 1Technical Details · 2026-05-23: 1Technical Details · 2026-06-07: 105-2306-0706-09
Signal classification2 categories
Disclosure
266.7%
Patch
133.3%
Referenced assets2 URLs
Classification over time
DateTotalLabels
2026-05-231
Disclosure1
2026-06-071
Patch1
2026-06-091
Disclosure1
Full discourse3 posts
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    Disclosure

    CVE-2026-6895 WordPress用WishList Memberプラグイン(バージョン3.30.1まで)の脆弱性をわかりやすく解説|影響範囲と対策まとめ https://www.cybernote.click/2026/06/06/cve-2026-6895-wordpresswishlist-member3301/ #IT #Security #cybersecurity

    Post summary

    The article announces and explains CVE-2026-6895 affecting WordPress WishList Member plugin up to v3.30.1, outlining its impact and providing mitigation steps.

    0000048
    209 followersView on X
  • ケイ | IT・セキュリティ系副業Webライター@Teeeda_worker
    Patch

    CVE-2026-6895 WordPress用WishList Memberプラグイン(バージョン3.30.1まで)の脆弱性をわかりやすく解説|影響範囲と対策まとめ https://www.cybernote.click/2026/06/06/cve-2026-6895-wordpresswishlist-member3301/ #IT #Security #cybersecurity

    Post summary

    The linked article explains CVE-2026-6895 affecting the WishList Member WordPress plugin, detailing its impact and providing countermeasures, but does not mention any PoC or exploit.

    0000032
    209 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-6895 The WishList Member plugin for WordPress is vulnerable to Missing Authorization leading to Sensitive Information Disclosure and Privilege Escalation in versions up to a… https://www.cve.org/CVERecord?id=CVE-2026-6895

    Post summary

    The WishList Member plugin for WordPress suffers from a missing authorization flaw that can expose sensitive information and enable privilege escalation; no proof‑of‑concept, active exploitation, or mitigation is reported.

    00000163
    57.5K followersView on X

Explore more