CVE-2026-6897

8.8

WishList Products · WishList Member

The WishList Member plugin for WordPress is vulnerable to unauthorized data modification due to a missing capability check.

Executive summary

A high-severity authorization vulnerability in the WishList Member WordPress plugin allows attackers to modify system settings by bypassing capability checks.

Vulnerability

The vulnerability exists in the 'WishListMember\Features\Team_Accounts::save_settings' function, which fails to verify user capabilities. This allows unauthorized users to modify plugin settings.

Business impact

A CVSS score of 8.8 indicates a high risk. Exploitation could allow an attacker to alter core plugin settings, potentially weakening the site's security posture or redirecting member traffic.

Remediation

Immediate Action: Update the WishList Member plugin to the latest version.

Proactive Monitoring: Regularly review plugin configuration settings for any unexpected changes.

Compensating Controls: Limit access to the WordPress backend to trusted network locations.

Exploitation status

Public Exploit Available: false

Analyst recommendation

Capability checks are fundamental to plugin security. Administrators should update the WishList Member plugin immediately to ensure that configuration settings are protected from unauthorized modification.

More WishList Products CVEs