Vendor
The Wishlist Member plugin for WordPress contains an account takeover vulnerability via insufficient verification of registration data in the wpm_register function, allowing unauthenticated attackers to overwrite administrator accounts.