Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
9.8

CVE-2026-13598: RestrictMate plugin lets anyone create admin account

CVE-2026-13598 · published 12 days ago
Summary

The RestrictMate add‑on for WordPress (versions before 1.3.0) does not check the role chosen when a new user signs up. This lets anyone on the internet register and become an administrator, giving them full control of the site. Update the plugin to the latest version or remove it if you cannot upgrade.

What to do
  • Update unknown restrictmate to version 1.3.0 or later.
Affected software
VendorProductAffected versions
unknown restrictmate < 1.3.0
Original advisory text
The RestrictMate WordPress plugin before 1.3.0 does not restrict the user role supplied during account registration, allowing unauthenticated attackers to create a new administrator account and ga...
The RestrictMate WordPress plugin before 1.3.0 does not restrict the user role supplied during account registration, allowing unauthenticated attackers to create a new administrator account and gain a logged-in administrator session, leading to full site takeover.
Severity
9.8 Critical
Exploitation
EPSS <1%
Type
CWE-269Improper Privilege Management
Timeline
Published23 Aug 2026
Updated30 Aug 2026
First seen23 Aug 2026
Sources
CVE-2026-13598 · MITRE
Monitor software like this
Free during beta