A vulnerability was found in Wishlist Member Plugin up to 3.34.1 on WordPress. It has been classified as critical. Affected by this vulnerability is the function wpm_register/wp_update_user of the component Registration. Performing a manipulation of the argument mergewith/wpm_id results in improper authentication.

This vulnerability is identified as CVE-2026-12949. The attack can be initiated remotely. There is not any exploit available.