← back
CVE-2026-13598

RestrictMate < 1.3.0 - Unauthenticated Privilege Escalation to Administrator

0Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Track
exploitation probability
observed exploitation
nono source reports it
The RestrictMate WordPress plugin before 1.3.0 does not restrict the user role supplied during account registration, allowing unauthenticated attackers to create a new administrator account and gain a logged-in administrator session, leading to full site takeover.
Affected products
Unknown · RestrictMate