Junglewise Threat Intelligence

CVE-2026-39588: nmerii NM Gift Registry and Wishlist Lite missing authorization

CVE-2026-39588 · Severity: medium · CVSS 5.3 · Published 2026-04-08

Executive brief

The NM Gift Registry and Wishlist Lite plugin for WordPress, which allows users to create and manage gift lists, contains a security flaw in its access control settings. This vulnerability allows unauthorized individuals to perform actions or modify settings that should be restricted to administrators or specific users. An exploit could lead to unauthorized changes to gift registries or site configurations, potentially disrupting the service or affecting user data integrity.

Technical details

A Missing Authorization (CWE-862) vulnerability exists in the nmerii NM Gift Registry and Wishlist Lite plugin for WordPress through version 5.13. The flaw stems from a failure to implement proper authorization checks or nonce validation on certain functions, allowing unauthenticated remote attackers to execute actions that should require higher privileges. This is classified as a Broken Access Control issue where security levels are incorrectly configured. Attackers can achieve partial integrity impact by modifying data or settings without authentication. The issue is resolved in version 5.14.

Affected products

  • nmerii NM Gift Registry and Wishlist Lite <= 5.13

Timeline

  • 2026-01-19: other: Vulnerability reported by researcher Legion Hunter
  • 2026-02-18: disclosed: Initial disclosure by Patchstack
  • 2026-04-08: advisory: CVE published to NVD
  • 2026-06-17: patched: Patch information confirmed for version 5.14

References