{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/wishlist-member/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-12949"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Wishlist Member"],"_cs_severities":["critical"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Wishlist Member"],"content_html":"\u003cp\u003eThe Wishlist Member plugin for WordPress (versions 3.34.1 and below) is susceptible to a critical account takeover vulnerability (CVE-2026-12949) caused by insufficient verification of data authenticity within the wpm_register() function. Attackers can exploit this flaw by submitting specific POST parameters (mergewith and wpm_id) to the registration endpoint. The plugin fails to verify if the mergewith parameter, which accepts a numeric WordPress user ID, is cryptographically bound to the current registration transaction.\u003c/p\u003e\n\u003cp\u003eBy supplying an arbitrary user ID, an attacker can force the application to execute wp_update_user() and a direct $wpdb UPDATE, overwriting the victim's credentials, email, and name. Critically, the plugin suppresses WordPress's built-in notification emails for password or email address changes. If the wpm_id parameter is set to a non-existent membership level, the plugin skips the role update, preserving the target user's existing permissions. This allows unauthenticated attackers to silently elevate their access to an administrator level, posing a significant risk to site integrity and data security.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker identifies a WordPress site running Wishlist Member \u0026lt;= 3.34.1.\u003c/li\u003e\n\u003cli\u003eAttacker enumerates the target's numeric User ID (e.g., ID 1 for administrator).\u003c/li\u003e\n\u003cli\u003eAttacker crafts a malicious POST request to the wpm_register() endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker includes the target's User ID in the 'mergewith' POST parameter.\u003c/li\u003e\n\u003cli\u003eAttacker includes a non-existent value in the 'wpm_id' parameter to bypass role modifications.\u003c/li\u003e\n\u003cli\u003eThe plugin processes the request and executes wp_update_user() and $wpdb updates using attacker-supplied credentials.\u003c/li\u003e\n\u003cli\u003eThe plugin suppresses standard WordPress security notification emails.\u003c/li\u003e\n\u003cli\u003eAttacker gains full unauthorized access to the target account, including administrative privileges.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows unauthenticated attackers to take over any existing user account, including those with administrator privileges. Given that the plugin suppresses security notifications, the compromise may go undetected by site owners. This leads to full administrative compromise, data exfiltration, backdooring, and potential full-site control.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the Wishlist Member plugin to a patched version beyond 3.34.1 immediately.\u003c/li\u003e\n\u003cli\u003eMonitor web server access logs for POST requests to registration endpoints containing the 'mergewith' and 'wpm_id' parameters.\u003c/li\u003e\n\u003cli\u003eImplement file integrity monitoring and database auditing to detect unauthorized modifications to the wp_users table.\u003c/li\u003e\n\u003cli\u003eReview web application logs (sc-status, cs-uri-stem) for suspicious registration patterns targeting high-privilege IDs.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-14T08:06:21Z","date_published":"2026-08-14T08:06:21Z","id":"https://feed.craftedsignal.io/briefs/2026-08-wishlist-member-ato/","summary":"The Wishlist Member plugin for WordPress contains an account takeover vulnerability via insufficient verification of registration data in the wpm_register function, allowing unauthenticated attackers to overwrite administrator accounts.","title":"CVE-2026-12949: Unauthenticated Account Takeover in Wishlist Member Plugin","url":"https://feed.craftedsignal.io/briefs/2026-08-wishlist-member-ato/"}],"language":"en","title":"CraftedSignal Threat Feed - Wishlist Member","version":"https://jsonfeed.org/version/1.1"}