Executive brief
WishList Member X is a WordPress plugin used to manage memberships and restricted content on websites. A security flaw allows users with basic 'Subscriber' accounts to upload malicious files to the server. This could lead to a complete takeover of the website, data theft, or the installation of backdoors.
Technical details
An unrestricted file upload vulnerability (CWE-434) exists in WishList Member X versions 3.29.0 and earlier. The flaw allows an authenticated attacker with Subscriber-level privileges to upload dangerous file types, such as PHP scripts, to the web server. Because the application fails to properly validate file extensions or content, an attacker can achieve remote code execution (RCE) by accessing the uploaded file. This vulnerability has a high impact on confidentiality, integrity, and availability, as indicated by its CVSS score of 9.9. As of the advisory date, no official patch has been released.
Affected products
- WishList Products, LLC. WishList Member X <= 3.29.0
Timeline
- 2025-12-21: other: Vulnerability reported by researcher Jarno Vos
- 2026-03-18: advisory: Patchstack published initial advisory details
- 2026-06-17: disclosed: CVE published to NVD