Executive brief
WishList Member X is a WordPress plugin used to manage memberships and restrict access to content. A security flaw allows users with basic 'Subscriber' accounts to bypass certain access controls, potentially viewing information they are not authorized to see. This could lead to unauthorized access to member-only content or internal site data.
Technical details
A broken access control vulnerability exists in WishList Member X versions up to and including 3.29.0. The issue stems from missing authorization checks (CWE-862) within the plugin's functions. An authenticated attacker with Subscriber-level privileges can exploit this over the network to perform actions or access data that should be restricted to higher-privileged roles. As of the advisory date, no official patch has been confirmed, though users are advised to monitor for updates from the vendor.
Affected products
- WishList Member WishList Member X <= 3.29.0
Timeline
- 2025-12-21: other: Reported by researcher 0xd4rk5id3
- 2026-01-20: disclosed: Initial disclosure by Patchstack
- 2026-06-17: advisory: NVD publication date