Vulnerabilities / WooCommerce / WPSEC-2026-0656

WooCommerce <= 11.1.2 - Authenticated (Shop Manager+) Privilege Escalation via Account Takeover through Password Reset Email Cc/Bcc Recipients

High 7.2 CWE-640Fixed in 11.2.0
ID
WPSEC-2026-0656
Plugin
WooCommerce (woocommerce)
Affected
from 9.8.0 before 11.2.0
Remediation
Update to 11.2.0 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness
CWE-640
Usage
Plugin High · Affected versions High among sites WPSec scans, 2026-10-08
Attack surface
WooCommerce on WPSec AttackSurface
Fix released
Published

Description

The WooCommerce plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in versions 9.8.0 up to, and including, 11.1.2. When the email improvements feature is enabled, the plugin allows Cc and Bcc recipients to be configured for every transactional email, including the Reset password email, which carries a password reset link. This makes it possible for authenticated attackers with Shop Manager-level access or higher, who can manage WooCommerce email settings, to receive the password reset links of other users, including administrators, and take over their accounts.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0