NVD CRITICAL: CVE-2026-12949 — The Wishlist Member plugin for WordPress is vulnerable to Account Takeover via I...
The Wishlist Member plugin for WordPress is vulnerable to Account Takeover via Insufficient Verification of Data Authenticity in versions up to and including 3.34.1. This is due to the wpm_register() function validating the registration cookie only against the GET reg parameter while accepting the POST mergewith and POST wpm_id parameters without verifying that the mergewith user ID references a t
CVE-2026-12949