# WooCommerce <= 11.1.2 - Authenticated (Shop Manager+) Privilege Escalation via Account Takeover through Password Reset Email Cc/Bcc Recipients

- **ID:** WPSEC-2026-0656
- **Plugin:** WooCommerce (`woocommerce`), https://wordpress.org/plugins/woocommerce/
- **Affected versions:** from 9.8.0 before 11.2.0
- **Fixed in:** 11.2.0 (Update to 11.2.0 or later.)
- **Severity:** High 7.2 (CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H)
- **Weakness:** CWE-640
- **Usage among sites WPSec scans:** plugin High, affected versions High (as of 2026-10-08)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/woocommerce
- **Fix released:** 2026-10-07
- **Published:** 2026-10-08
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0656/

## Description

The WooCommerce plugin for WordPress is vulnerable to Privilege Escalation via Account Takeover in versions 9.8.0 up to, and including, 11.1.2. When the email improvements feature is enabled, the plugin allows Cc and Bcc recipients to be configured for every transactional email, including the Reset password email, which carries a password reset link. This makes it possible for authenticated attackers with Shop Manager-level access or higher, who can manage WooCommerce email settings, to receive the password reset links of other users, including administrators, and take over their accounts.

## References

- https://wpsec.com/vuln/WPSEC-2026-0656/
- https://plugins.svn.wordpress.org/woocommerce/tags/11.2.0/
- https://wordpress.org/plugins/woocommerce/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0656/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
