Role Assignment Vulnerability in WooCommerce WordPress Plugin
CVE-2026-81431
Key Information:
- Vendor
WordPress
- Vendor
- CVE Published:
- 10 September 2026
Badges
What is CVE-2026-81431?
The WooCommerce plugin for WordPress, prior to version 1.1.3, contains a vulnerability in its Registration Form functionality. It fails to properly validate the legitimacy of the registration form, inadvertently allowing users with post-creation capabilities (Contributors and above) to register with arbitrary roles, including the highly privileged Administrator role. This flaw opens the door for complete site takeover, as unauthorized users can manipulate their access levels, posing a significant risk to website security. This vulnerability builds upon an incomplete fix from a previous issue, highlighting the importance of robust input validation in safeguarding WordPress sites.
Affected Version(s)
Registration Form for WooCommerce 1.1.0 < 1.1.3
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.