What is CVE-2026-12949?
The Wishlist Member plugin for WordPress (version up to 3.34.1) is affected by CVE-2026-12949, which allows Account Takeover due to insufficient verification of data authenticity in the wpm_register() function. The vulnerability arises from the validation of the registration cookie only against the GET reg parameter. Users should immediately update the plugin to the latest version.
Azərbaycanca: WordPress üçün Wishlist Member plaginində (versiya 3.34.1 və aşağı) CVE-2026-12949 zəifliyi aşkar edilib. wpm_register() funksiyasında kifayət qədər məlumat autentifikasiyası olmaması səbəbindən hesab ələ keçirmə (Account Takeover) mümkündür. Plagindən istifadə edən saytlar dərhal ən son versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-287
FAQ2
Which WordPress plugin is affected by CVE-2026-12949?
This vulnerability affects the Wishlist Member plugin for WordPress, versions 3.34.1 and below.
What causes the CVE-2026-12949 vulnerability?
It is caused by insufficient data authenticity verification in the wpm_register() function, where the registration cookie is only validated against the GET reg parameter.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.