CVE-2026-12949

cvss 9.8

A flaw in the WordPress Wishlist Member plugin allows attackers to hijack user accounts by manipulating registration data, which could lead to unauthorized access to your site's content and user information.

Patch now

why it matters — synthesized by an LLM from the sources below

signal timeline

first seen 54m ago · last seen 8m ago

intelyard daily

One short email each weekday: what mattered in tech, written from source data and checked by a human. No account needed, one-click unsubscribe, and we never sell or share the address.