Impact
The Wishlist Member plugin up to version 3.34.1 contains a flaw in the wpm_register() function that only verifies the registration cookie against a GET parameter while accepting POST parameters mergewith and wpm_id without proper validation. An unauthenticated attacker can supply any numeric user ID as mergewith, causing WordPress to update that user’s credentials and personal details, suppressing notification emails. If wpm_id refers to a non‑existent membership level, the existing role, including administrator, remains unchanged, giving the attacker full privileges.
Affected Systems
WordPress sites that use the Wishlist Member plugin in version 3.34.1 or earlier are directly affected. No other vendors or products are listed as impacted.
Risk and Exploitability
The CVSS score of 9.8 indicates critical severity. While an EPSS score is not available, the vulnerability requires only an unauthenticated HTTP request, making it potentially exploitable by widespread automation. It is not currently listed in CISA KEV, but the attack vector is clear: a crafted request to the plugin’s registration endpoint can result in complete account takeover and privilege escalation.
OpenCVE Enrichment