CRITICAL
9.8 CVE-2026-13598 Published 23 Aug 2026
WordPress RestrictMate Plugin Admin Takeover
Worried this affects one of your servers?
The RestrictMate WordPress plugin, versions prior to 1.3.0, has a critical vulnerability.
RestrictMate does not validate or restrict the user role during account registration, allowing unauthenticated attackers to create a new administrator account.
Exploitation of this vulnerability leads to a full site takeover.
Reference: CVE-2026-13598 on NVD
← Back to Security News