{
 "id": "WPSEC-2026-0656",
 "url": "https://wpsec.com/vuln/WPSEC-2026-0656/",
 "json_url": "https://wpsec.com/vuln/WPSEC-2026-0656/advisory.json",
 "markdown_url": "https://wpsec.com/vuln/WPSEC-2026-0656/index.md",
 "title": "WooCommerce <= 11.1.2 - Authenticated (Shop Manager+) Privilege Escalation via Account Takeover through Password Reset Email Cc/Bcc Recipients",
 "description": "The WooCommerce plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in versions 9.8.0 up to, and including, 11.1.2. When the email improvements feature is enabled, the plugin allows Cc and Bcc recipients to be configured for every transactional email, including the Reset password email, which carries a password reset link. This makes it possible for authenticated attackers with Shop Manager-level access or higher, who can manage WooCommerce email settings, to receive the password reset links of other users, including administrators, and take over their accounts.",
 "plugin": {
  "slug": "woocommerce",
  "name": "WooCommerce",
  "full_name": "WooCommerce",
  "wordpress_org": "https://wordpress.org/plugins/woocommerce/",
  "advisories_url": "https://wpsec.com/vuln/plugin/woocommerce/",
  "attacksurface": "https://attacksurface.wpsec.com/plugin/woocommerce"
 },
 "type": "PRIV",
 "cwe": [
  "CWE-640"
 ],
 "cve": [],
 "cvss": {
  "version": "3.1",
  "score": 7.2,
  "vector": "CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H",
  "severity": "High"
 },
 "affected": {
  "ranges": [
   {
    "from": "9.8.0",
    "from_inclusive": true,
    "to": "11.2.0",
    "to_inclusive": false
   }
  ],
  "text": [
   "from 9.8.0 before 11.2.0"
  ]
 },
 "introduced_in": "9.8.0",
 "fixed_in": "11.2.0",
 "remediation": "Update to 11.2.0 or later.",
 "fix_released": "2026-10-07T14:05:26+00:00",
 "published": "2026-10-08T14:54:41+00:00",
 "updated": "2026-10-07T18:24:36.855520+00:00",
 "also_published_as": null,
 "references": [
  "https://wpsec.com/vuln/WPSEC-2026-0656/",
  "https://plugins.svn.wordpress.org/woocommerce/tags/11.2.0/",
  "https://wordpress.org/plugins/woocommerce/"
 ],
 "attacksurface_url": "https://attacksurface.wpsec.com/plugin/woocommerce",
 "source": "WPSec",
 "license": {
  "name": "CC BY 4.0",
  "url": "https://creativecommons.org/licenses/by/4.0/"
 },
 "usage": {
  "plugin": "High",
  "affected_versions": "High",
  "as_of": "2026-10-08"
 }
}