External risk intelligence

RestrictMate WordPress Plugin Account Registration Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-13598

The vulnerability affects a WordPress plugin registration mechanism. Registration forms are public-facing by design in standard WordPress deployments, allowing unauthenticated internet access to the affected endpoint.

Halo Surface Signal: 5 out of 5 — more likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability allows unauthorized individuals to create new administrator accounts on affected websites without needing any credentials. The issue lies within the RestrictMate WordPress plugin, potentially enabling attackers to take full control of a website.

  • Anyone can create an admin account.
  • Remember this allows site takeover.
  • Confirm if your site uses this plugin.

Attack Path

How an attacker could exploit the issue

An attacker can exploit this vulnerability by sending a specially crafted request to a WordPress site that has the RestrictMate plugin installed. This request allows them to register a new user with administrator privileges without needing any prior authentication or existing account. Once this new administrator account is created, the attacker can use it to log in and take complete control of the website.

  • Unauthenticated network access required.
  • Registering a new administrator account.
  • Full website takeover.

Live Threat

Current exploitation, exposure, and threat context

Unauthenticated attackers could create a new administrator account through the RestrictMate WordPress plugin when supported by the advisory. This could lead to full site takeover by gaining a logged-in administrator session.

  • WordPress site administration.
  • Unauthenticated account creation.
  • Full site takeover.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in the RestrictMate WordPress plugin allows unauthenticated attackers to create administrator accounts, leading to a full site takeover. Ownership likely resides with the application or platform team managing the WordPress instances. The first step is to identify all WordPress sites utilizing the RestrictMate plugin, assess their internet exposure and business criticality, and then engage with the site owner to prioritize remediation.

  • Application owners must own the remediation.
  • Verify internet-exposed WordPress instances.
  • Plan for vendor coordination and updates.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is the RestrictMate WordPress plugin?

RestrictMate is a component designed for WordPress sites to manage user access and registration settings. It helps site administrators control how new users join the platform, often by restricting registration roles or membership levels to specific groups. When integrated into a site, it interacts directly with the standard WordPress user registration workflow to enforce these access rules during account creation.

What does CWE-269 mean for CVE-2026-13598?

CWE-269 refers to Improper Privilege Management. In the context of this CVE, it means the plugin fails to correctly verify or limit the permission level assigned to new accounts. Instead of assigning a standard, limited role to a new user, the software mistakenly allows an attacker to specify and receive administrative privileges, granting them high-level control over the website's functions and settings.

How does an attacker trigger this vulnerability?

An attacker triggers the bug by submitting a registration request to the site that includes malicious data intended to elevate their account role. The vulnerability specifically targets the registration endpoint; it does not require an existing account or password to function. Simply browsing the site normally without attempting to register a new user will not trigger the vulnerability.

Why is this CVE considered high risk by Halo Surface Signal?

Halo Surface Signal identifies this as a significant risk because the affected registration mechanism is designed to be public-facing. Since WordPress registration forms are typically accessible over the internet to allow new members to join, the vulnerable endpoint is exposed by default. This enables unauthenticated attackers to interact with the registration process directly from the public internet.

What should I do if I run RestrictMate?

Your first step is to inventory your environment to identify all WordPress instances where the RestrictMate plugin is active. Once located, verify if you are running a version prior to 1.3.0, as these are the affected versions. Coordinate with your site administrators to immediately disable the plugin or restrict access to registration pages until you can apply the vendor-provided update.

References