A vulnerability was found in Wishlist Member Plugin up to 3.34.1 on WordPress. It has been classified as critical. Affected by this vulnerability is the function
wpm_register/wp_update_user of the component Registration. Performing a manipulation of the argument mergewith/wpm_id results in improper authentication.
This vulnerability is identified as CVE-2026-12949. The attack can be initiated remotely. There is not any exploit available.