Privilege Escalation in Custom User Registration Fields for WooCommerce Plugin
CVE-2026-15369

9.8CRITICAL

What is CVE-2026-15369?

The Custom User Registration Fields for WooCommerce plugin allows unauthenticated users to exploit a vulnerability that can lead to privilege escalation. In versions up to and including 2.2.3, the plugin processes an attacker-controlled 'afreg_select_user_role' value through the WooCommerce Store API during checkout. This compromised value is directly passed to the WP_User::add_role() function without sufficient validation against the admin-configured roles. If the 'User Role Selection' feature is enabled, attackers can create accounts with elevated privileges, such as Administrator, by manipulating the JSON body of the checkout request.

Affected Version(s)

Custom User Registration Fields for WooCommerce 0 <= 2.2.3

References

CVSS V3.1

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

0xd4rk5id3
.