Loading market data...
← Back to CVE feed

CVE-2026-13598

UNKNOWN View on NVD ↗

Description

The RestrictMate WordPress plugin before 1.3.0 does not restrict the user role supplied during account registration, allowing unauthenticated attackers to create a new administrator account and gain a logged-in administrator session, leading to full site takeover.

Published: Aug 23, 2026 06:16 UTC Modified: Aug 23, 2026 06:16 UTC