Role Assignment Vulnerability in WooCommerce WordPress Plugin
CVE-2026-81431

Currently unrated

Key Information:

Vendor

WordPress

Vendor
CVE Published:
10 September 2026

Badges

๐Ÿ‘พ Exploit Exists๐ŸŸก Public PoC

What is CVE-2026-81431?

The WooCommerce plugin for WordPress, prior to version 1.1.3, contains a vulnerability in its Registration Form functionality. It fails to properly validate the legitimacy of the registration form, inadvertently allowing users with post-creation capabilities (Contributors and above) to register with arbitrary roles, including the highly privileged Administrator role. This flaw opens the door for complete site takeover, as unauthorized users can manipulate their access levels, posing a significant risk to website security. This vulnerability builds upon an incomplete fix from a previous issue, highlighting the importance of robust input validation in safeguarding WordPress sites.

Affected Version(s)

Registration Form for WooCommerce 1.1.0 < 1.1.3

Exploit Proof of Concept (PoC)

PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.

References

Timeline

  • ๐ŸŸก

    Public PoC available

  • ๐Ÿ‘พ

    Exploit known to exist

  • Vulnerability published

  • Vulnerability Reserved

Credit

Sai Praneeth Koti
WPScan
.