Privilege Escalation in Wpify Woo Plugin for WordPress
CVE-2026-12736
8HIGH
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 24 July 2026
What is CVE-2026-12736?
The Wpify Woo plugin for WordPress is susceptible to a privilege escalation vulnerability. This arises from the SettingsApi::save_option() REST route, which allows authenticated users with Shop Manager-level access to manipulate crucial option parameters without appropriate validation or sanitization. The vulnerability permits attackers to elevate their privileges to Administrator by changing WordPress options such as setting default roles and disabling security plugins, thereby compromising the site’s overall integrity.
Affected Version(s)
WPify Woo – Withdrawal, CRN/VAT, QR payments, Heureka and more for WooCommerce 0 <= 5.4.16