Junglewise Threat Intelligence

CVE-2026-6897: WishList Member privilege escalation in Team_Accounts

CVE-2026-6897 · Severity: high · CVSS 8.8 · Published 2026-05-23

Technologies: WishList Member. Vendors: WishList Member.

Executive brief

The WishList Member plugin for WordPress, which is used to manage memberships and protect premium content, contains a security flaw that allows users with basic account access to modify site settings. An attacker with a simple subscriber account could exploit this to grant themselves administrative privileges. This can lead to a complete takeover of the website, allowing the attacker to access sensitive customer data or shut down the service.

Technical details

The WishList Member plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'WishListMember\Features\Team_Accounts::save_settings' function. This vulnerability affects all versions up to and including 3.30.1. An authenticated attacker with Subscriber-level permissions or higher can exploit this flaw to update arbitrary plugin options. Specifically, an attacker can modify the REST API Secret Key to create a new membership level with the WordPress 'administrator' role and register a new admin user. This results in a full privilege escalation and complete site takeover. The attack is reachable over the network and requires only low-level authenticated access.

Affected products

  • WishList Member WishList Member up to, and including, 3.30.1

Timeline

  • 2026-05-23: disclosed: Initial advisory publication

References

Related threats