The Wishlist Member plugin for WordPress is vulnerable to Account Takeover via Insufficient Verification of Data Authenticity in versions up to and including 3.34.1. This is due to the wpm_register() function validating the registration cookie only against the GET reg parameter while accepting the POST mergewith and POST wpm_id parameters without verifying that the mergewith user ID references a temporary or incomplete registrant that is bound to the current registration transaction. This makes it possible for unauthenticated attackers to take over any existing WordPress account — including administrator accounts — by supplying an arbitrary user's numeric ID as the mergewith value, which causes wp_update_user() to overwrite the target account's username (additionally written via a direct $wpdb UPDATE), password, email address, first name, and last name with attacker-controlled values, while WordPress password and email change notification emails are explicitly suppressed. When wpm_id references a non-existent membership level, no role key is added to the update payload, causing wp_update_user() to preserve the target user's existing role — including administrator — making full privilege escalation a direct consequence of the takeover.
We have discovered 1,368 live websites that are affected by CVE-2026-12949.
| Product | |
| Category | Wordpress Plugins |
| Vulnerable Domains | 1,368 live websites (100% of WishList Member install base) |
| Vulnerable Versions |
|
| Vulnerable Versions Count | 123 versions ( 99% of all versions) |
| 926 websites | |
| 84 websites | |
| 45 websites | |
| 41 websites | |
| 35 websites | |
| 34 websites | |
| 29 websites | |
| 21 websites | |
| 19 websites | |
| 18 websites |
| .com | 988 websites |
| .org | 71 websites |
| .nl | 70 websites |
| .net | 30 websites |
| .co.uk | 16 websites |
| .fr | 16 websites |
| .com.au | 14 websites |
| .it | 13 websites |
| .de | 10 websites |
| .ru | 6 websites |
| Domain | Country | Rank | Contacts |
|---|---|---|---|
| *********.com | **,*** | ||
| *******.com | **,*** | ||
| *****.clinic | **,*** | ||
| *********************.com | **,*** | ||
| *****************.com | ***,*** | ||
| *****.***.au | ***,*** | ||
| *******************.com | ***,*** | ||
| ****************.com | ***,*** | ||
| ****************.com | ***,*** | ||
| ******************.org | ***,*** |
FAQ