SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-13598

CRITICAL · CVSS 9.8 EPSS 0.30%

Source: NVD + CISA KEV + EPSS · Published 2026-08-23 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The RestrictMate WordPress plugin prior to version 1.3.0 is vulnerable due to inadequate restrictions on user roles during account registration, enabling unauthenticated attackers to create an administrator account. This flaw can lead to a complete site takeover, compromising the integrity and security of the affected WordPress installations. WordPress site administrators using this plugin should prioritize immediate updates to mitigate the risk of unauthorized access.

CVE
CVE-2026-13598
Severity
CRITICAL
CVSS
9.8
EPSS
0.30%
WordPress

Original NVD Description

The RestrictMate WordPress plugin before 1.3.0 does not restrict the user role supplied during account registration, allowing unauthenticated attackers to create a new administrator account and gain a logged-in administrator session, leading to full site takeover.