Junglewise Threat Intelligence

CVE-2026-6898: WishList Member WordPress plugin privilege escalation

CVE-2026-6898 · Severity: high · CVSS 8.8 · Published 2026-05-23

Technologies: WishList Member. Vendors: WishList Member.

Executive brief

The WishList Member plugin for WordPress, which is used to manage memberships and protect site content, contains a security flaw that allows users with basic account access to take over the entire website. By exploiting a missing security check, an attacker can reset the site's API keys to gain administrative control. This could lead to the theft of member data, site defacement, or the creation of unauthorized administrator accounts.

Technical details

The WishList Member plugin for WordPress is vulnerable to an authorization bypass due to a missing capability check on the 'WishListMember3_Hooks::generate_api_key' function. This flaw exists in all versions up to and including 3.30.1. An authenticated attacker with Subscriber-level permissions or higher can trigger this function to update the REST API Secret Key. By manipulating this key, the attacker can create a new membership level with the WordPress 'administrator' role and register a new user account assigned to that level. This sequence of actions results in a complete privilege escalation and site takeover. The vulnerability is reachable via the network and requires only low-level authenticated access.

Affected products

  • WishList Member WishList Member up to, and including, 3.30.1

Timeline

  • 2026-05-23: disclosed: Vulnerability published to NVD

References

Related threats