Privilege Escalation in Custom User Registration Fields for WooCommerce Plugin
CVE-2026-15369
9.8CRITICAL
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 29 August 2026
What is CVE-2026-15369?
The Custom User Registration Fields for WooCommerce plugin allows unauthenticated users to exploit a vulnerability that can lead to privilege escalation. In versions up to and including 2.2.3, the plugin processes an attacker-controlled 'afreg_select_user_role' value through the WooCommerce Store API during checkout. This compromised value is directly passed to the WP_User::add_role() function without sufficient validation against the admin-configured roles. If the 'User Role Selection' feature is enabled, attackers can create accounts with elevated privileges, such as Administrator, by manipulating the JSON body of the checkout request.
Affected Version(s)
Custom User Registration Fields for WooCommerce 0 <= 2.2.3