Feed/CVE-2026-13598
CVE-2026-13598

CVE-2026-13598

Published Aug 23, 2026·Updated Aug 23, 2026

NVD Description

The RestrictMate WordPress plugin before 1.3.0 does not restrict the user role supplied during account registration, allowing unauthenticated attackers to create a new administrator account and gain a logged-in administrator session, leading to full site takeover.

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free