Vulnerabilities / WooCommerce / WPSEC-2026-0657

WooCommerce <= 11.1.2 - Authenticated (Shop Manager+) Privilege Escalation via Editing Users with Multiple Roles

Medium 6.6 CWE-863Fixed in 11.2.0
ID
WPSEC-2026-0657
Plugin
WooCommerce (woocommerce)
Affected
all versions before 11.2.0
Remediation
Update to 11.2.0 or later.
CVSS 3.1
CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H
Weakness
CWE-863
Usage
Plugin High · Affected versions High among sites WPSec scans, 2026-10-08
Attack surface
WooCommerce on WPSec AttackSurface
Fix released
Published

Description

The WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 11.1.2. This is due to the checks that restrict shop managers to editing customers treating a user as editable when any one of the user's roles is editable (by default 'customer'), instead of requiring all of the user's roles to be editable, and to the REST API customers endpoint restricting email and password changes based only on the user's primary role. This makes it possible for authenticated attackers with Shop Manager-level access to change the email address and password of users who hold the customer role together with a higher-privileged role, including administrator when customer is the user's primary role, and take over those accounts. Exploitation requires such a multi-role user to exist, which is only possible when another plugin assigns additional roles.

References

Published by WPSec. Provided as is, without warranty. Corrections: contact us.

This advisory as JSON or Markdown · All advisories: JSON, RSS

License: CC BY 4.0