WooCommerce <= 11.1.2 - Authenticated (Shop Manager+) Privilege Escalation via Account Takeover through Password Reset Email Cc/Bcc Recipients
- ID
- WPSEC-2026-0656
- Plugin
- WooCommerce (woocommerce)
- Affected
- from 9.8.0 before 11.2.0
- Remediation
- Update to 11.2.0 or later.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- Weakness
- CWE-640
- Usage
- Plugin High · Affected versions High among sites WPSec scans, 2026-10-08
- Attack surface
- WooCommerce on WPSec AttackSurface
- Fix released
- Published
Description
The WooCommerce plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in versions 9.8.0 up to, and including, 11.1.2. When the email improvements feature is enabled, the plugin allows Cc and Bcc recipients to be configured for every transactional email, including the Reset password email, which carries a password reset link. This makes it possible for authenticated attackers with Shop Manager-level access or higher, who can manage WooCommerce email settings, to receive the password reset links of other users, including administrators, and take over their accounts.
References
- https://wpsec.com/vuln/WPSEC-2026-0656/
- https://plugins.svn.wordpress.org/woocommerce/tags/11.2.0/
- https://wordpress.org/plugins/woocommerce/
Published by WPSec. Provided as is, without warranty. Corrections: contact us.
This advisory as JSON or Markdown · All advisories: JSON, RSS