The RestrictMate WordPress plugin before 1.3.0 does not restrict the user role supplied during account registration, allowing unauthenticated attackers to create a new administrator account and gain a logged-in administrator session, leading to full site takeover.
CVE-2026-13598
NONE
EPSS 0.19%
Updated Aug 23, 2026
WordPress
unknown:restrictmate
CVE Details
CVE ID
CVE-2026-13598
Published Date
Aug 23, 2026
Vendor
WordPress
Severity
NONE
Exploit Prediction (EPSS)
Probability of Exploit
0.19%
Likelihood of exploitation in next 30 days
Percentile:
8.5th percentile (higher than 8.5% of all CVEs)
Standard patching cycle
Impact
Minimal impact
Source
View Advisory