CRITICAL 9.8 CVE-2026-13598 Published 23 Aug 2026

WordPress RestrictMate Plugin Admin Takeover

Worried this affects one of your servers?

The RestrictMate WordPress plugin, versions prior to 1.3.0, has a critical vulnerability.

RestrictMate does not validate or restrict the user role during account registration, allowing unauthenticated attackers to create a new administrator account.

Exploitation of this vulnerability leads to a full site takeover.

Reference: CVE-2026-13598 on NVD

← Back to Security News