CVE-2026-13598
Published Aug 23, 2026
Last updated a day ago
- Description
- The RestrictMate WordPress plugin before 1.3.0 does not restrict the user role supplied during account registration, allowing unauthenticated attackers to create a new administrator account and gain a logged-in administrator session, leading to full site takeover.
- Source
- contact@wpscan.com
- NVD status
- Received
- Hype score
- Not currently trending
CVE-2026-13598 The RestrictMate WordPress plugin before 1.3.0 does not restrict the user role supplied during account registration, allowing unauthenticated attackers to create a n… https://t.co/FOurxz15Ve
@CVEnew
23 Aug 2026
817 Impressions
0 Retweets
0 Likes
0 Bookmarks
0 Replies
0 Quotes
CVE-2026-13598 Unauthenticated Administrator Account Creation in RestrictMate Wo... https://t.co/UX91wi6H8L Customizable Vulnerability Alerts: https://t.co/U7998fz7yk
@VulmonFeeds
23 Aug 2026
73 Impressions
0 Retweets
0 Likes
1 Bookmark
0 Replies
0 Quotes