UNKNOWN NVD

CVE-2026-13598

The RestrictMate WordPress plugin before 1.3.0 does not restrict the user role supplied during account registration, allowing unauthenticated attackers to crea

The RestrictMate WordPress plugin before 1.3.0 does not restrict the user role supplied during account registration, allowing unauthenticated attackers to create a new administrator account and gain a logged-in administrator session, leading to full site takeover.

References

Published: 2026-08-23 · Source: NVD · Feed updated: 2026-08-23
This unknown severity vulnerability was published on 2026-08-23 via NVD.
vulnfeed aggregates 10950 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.