Skip to main content

Threat intelligence

Wishlist Member <= 3.32.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Options Update via 'wishlistmember_team_accounts_save_settings' AJAX action

CVE-2026-6897 · wishlist-member-x

Important: Seeing this vulnerability listed does not mean your website is affected. Exposure depends on whether you run Wishlist Member X at a vulnerable version. How SiteRespond intelligence works

Vulnerability
Wishlist Member <= 3.32.0 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Plugin Options Update via 'wishlistmember_team_accounts_save_settings' AJAX action
Affected software
wishlist-member-x(Plugin)
Affected versions
  • ≤ 3.32.0
Authentication
Authenticated (see advisory title)
Vulnerability type
Other
Published
22 May 2026
CISA KEV
Not listed in CISA KEV at last catalog refresh
Impact
This advisory describes a other issue in the affected software. Review the source advisory and your installed version to assess exposure.
Source

Data imported from Wordfence Intelligence (advisory db251792-cbad-41e1-aaca-4cd39a25b444). Methodology and redistribution notes

Check whether your installed version is affected

SiteRespond Defence matches your installed Wishlist Member X version against this catalog when the Defence plugin is connected to your WordPress site.