Executive brief
The WishList Member plugin for WordPress, which is used to manage membership sites and restrict content, contains a security flaw that allows authenticated users to gain full administrative control of the website. By exploiting a lack of proper authorization checks, an attacker can obtain sensitive API keys and use them to create a new administrator account. This could lead to a complete site takeover, loss of customer data, and disruption of business operations.
Technical details
The WishList Member plugin for WordPress is vulnerable to privilege escalation due to missing capability checks in the 'export_settings' function. An authenticated attacker with low-level permissions can trigger this function via an AJAX request to receive a JSON response containing the REST API Secret Key. With this key, the attacker can authenticate to the WishList Member API, create a new membership level with the WordPress 'administrator' role, and register a new user account assigned to that level. This sequence allows for a complete site takeover. The vulnerability is present in all versions up to and including 3.30.1.
Affected products
- WishList Member WishList Member up to and including 3.30.1
Timeline
- 2026-05-23: disclosed
- 2026-05-23: advisory