# WooCommerce <= 11.1.2 - Authenticated (Shop Manager+) Privilege Escalation via Editing Users with Multiple Roles

- **ID:** WPSEC-2026-0657
- **Plugin:** WooCommerce (`woocommerce`), https://wordpress.org/plugins/woocommerce/
- **Affected versions:** all versions before 11.2.0
- **Fixed in:** 11.2.0 (Update to 11.2.0 or later.)
- **Severity:** Medium 6.6 (CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:H/I:H/A:H)
- **Weakness:** CWE-863
- **Usage among sites WPSec scans:** plugin High, affected versions High (as of 2026-10-08)
- **Attack surface analysis:** https://attacksurface.wpsec.com/plugin/woocommerce
- **Fix released:** 2026-10-07
- **Published:** 2026-10-08
- **URL:** https://wpsec.com/vuln/WPSEC-2026-0657/

## Description

The WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 11.1.2. This is due to the checks that restrict shop managers to editing customers treating a user as editable when any one of the user's roles is editable (by default 'customer'), instead of requiring all of the user's roles to be editable, and to the REST API customers endpoint restricting email and password changes based only on the user's primary role. This makes it possible for authenticated attackers with Shop Manager-level access to change the email address and password of users who hold the customer role together with a higher-privileged role, including administrator when customer is the user's primary role, and take over those accounts. Exploitation requires such a multi-role user to exist, which is only possible when another plugin assigns additional roles.

## References

- https://wpsec.com/vuln/WPSEC-2026-0657/
- https://plugins.svn.wordpress.org/woocommerce/tags/11.2.0/
- https://wordpress.org/plugins/woocommerce/

Source: WPSec, https://wpsec.com/vuln/WPSEC-2026-0657/

License: CC BY 4.0 (https://creativecommons.org/licenses/by/4.0/). Free to use, share and adapt, also commercially, if you credit WPSec and link to this advisory.
