CRITICAL

CVE-2026-12949

Wishlist Member X <= 3.34.1 - Unauthenticated Account Takeover via 'mergewith' Parameter

CVSS v3

9.8

CRITICAL

EPSS Score

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

The Wishlist Member plugin for WordPress is vulnerable to Account Takeover via Insufficient Verification of Data Authenticity in versions up to and including 3.34.1. This is due to the wpm_register() function validating the registration cookie only against the GET reg parameter while accepting the POST mergewith and POST wpm_id parameters without verifying that the mergewith user ID references a temporary or incomplete registrant that is bound to the current registration transaction. This makes

Technical details

CVSS v3 Vector
3.1
Published
8/14/2026
Last Modified
8/14/2026

Frequently asked questions

What is CVE-2026-12949?

The Wishlist Member plugin for WordPress is vulnerable to Account Takeover via Insufficient Verification of Data Authenticity in versions up to and including 3.34.1. This is due to the wpm_register() function validating the registration cookie only against the GET reg parameter while accepting the POST mergewith and POST wpm_id parameters without verifying that the mergewith user ID references a temporary or incomplete registrant that is bound to the current registration transaction. This makes

Is CVE-2026-12949 actively exploited?

Active exploitation of CVE-2026-12949 has not been confirmed. The EPSS score is N/A%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2026-12949?

CVE-2026-12949 has a CVSS v3 base score of 9.8 (CRITICAL severity), with vector string 3.1.

Is CVE-2026-12949 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.