Junglewise Threat Intelligence

CVE-2026-24575: WishList Member WishList Member X broken access control

CVE-2026-24575 · Severity: medium · CVSS 4.3 · Published 2026-06-17

Technologies: WishList Member. Vendors: WishList Member.

Executive brief

WishList Member X is a WordPress plugin used to manage memberships and restrict access to content. A security flaw allows users with basic 'Subscriber' accounts to bypass certain access controls, potentially viewing information they are not authorized to see. This could lead to unauthorized access to member-only content or internal site data.

Technical details

A broken access control vulnerability exists in WishList Member X versions up to and including 3.29.0. The issue stems from missing authorization checks (CWE-862) within the plugin's functions. An authenticated attacker with Subscriber-level privileges can exploit this over the network to perform actions or access data that should be restricted to higher-privileged roles. As of the advisory date, no official patch has been confirmed, though users are advised to monitor for updates from the vendor.

Affected products

  • WishList Member WishList Member X <= 3.29.0

Timeline

  • 2025-12-21: other: Reported by researcher 0xd4rk5id3
  • 2026-01-20: disclosed: Initial disclosure by Patchstack
  • 2026-06-17: advisory: NVD publication date

References

Related threats