Junglewise Threat Intelligence

CVE-2026-13598: RestrictMate privilege escalation in user registration

CVE-2026-13598 · Severity: critical · CVSS 9.8 · Published 2026-08-23

Vendors: Automattic.

Executive brief

RestrictMate is a WordPress plugin that manages user registration and roles. The plugin's registration form fails to validate the user role submitted during account creation, allowing anyone to register as an administrator without authentication. An attacker can exploit this to create a new admin account and immediately gain full control of the WordPress site.

Technical details

The vulnerability is a privilege escalation due to improper input validation in the user registration AJAX endpoint (action=restrictmate_registration). The plugin accepts a user-supplied "role" parameter during registration without restricting it to safe defaults, allowing an attacker to set role=administrator. The registration nonce is public and tied to the anonymous user (uid 0), making it scrapeable from the public /register page. An unauthenticated attacker can obtain the nonce, POST a crafted registration request with administrator privileges, and receive a logged-in session cookie immediately upon success. Fixed in version 1.3.0, which enforces a subscriber role regardless of the supplied role parameter.

Affected products

  • Automattic RestrictMate before 1.3.0

Timeline

  • 2026-08-21: disclosed
  • 2026-08-21: patched: Fixed in version 1.3.0

References