Sceawere
Vulnerability Detail
CVE-2026-106608UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
WooCommerce Privilege Escalation Vulnerability
Vulnerability Metadata
- Severity
- High
- Score / CVSS
- 7.2
- Creation Date
- 3h ago
- Vendor
- Automattic
- Product
- WooCommerce
- Attack Type
- Incorrect Privilege Assignment
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Incorrect Privilege Assignment vulnerability in Automattic WooCommerce woocommerce allows Privilege Escalation.This issue affects WooCommerce: from 9.8.0 through 11.1.2.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "7.2",
"pubDate": "2026-10-10T17:17:00.190Z",
"pubdate": "2026-10-10T17:17:00.190Z",
"executiveSummary": "This vulnerability is classified as an Incorrect Privilege Assignment, impacting the Automattic WooCommerce plugin across versions 9.8.0 through 11.1.2.\nThe flaw allows an authenticated user to escalate their current privilege level, potentially gaining unauthorized access to administrative or higher-level capabilities within the WordPress environment.\nThe vulnerability stems from improper validation or assignment logic during user role handling, which an attacker can manipulate to bypass established access control lists (ACLs).\nExploitation of this vulnerability poses a significant risk to system integrity, as a successful attack could grant an adversary full control over the WooCommerce storefront and underlying WordPress installation.\nAttackers require existing low-level access to the application to initiate the exploitation process. Once escalated, the attacker gains the permissions associated with the higher-level role, leading to potential unauthorized data exfiltration, configuration changes, or the installation of malicious code.",
"technicalDetails": "The vulnerability resides in the core privilege management logic of the WooCommerce plugin, specifically within the mechanisms responsible for assigning or updating user roles and capabilities.\nAt its core, the issue involves a failure in the input sanitization or authorization check process when the plugin handles user-related state transitions or metadata updates.\nUnder normal operations, WooCommerce relies on WordPress's internal capability system to manage access. However, in the affected versions (9.8.0 through 11.1.2), the plugin introduces logic that improperly validates the context of a request that modifies user privileges.\nThe attack flow typically follows this sequence: 1) An attacker authenticates as a user with limited permissions (e.g., a 'Customer' or 'Subscriber' role). 2) The attacker identifies a request, such as a profile update, account registration, or specific API call, that interacts with the user metadata or role assignment functions within WooCommerce. 3) By injecting crafted parameters—such as manipulated role identifiers or unauthorized field modifications—the attacker triggers the vulnerable function to perform an insecure update. 4) The server-side logic fails to enforce proper boundary checks, resulting in the application assigning elevated capabilities to the attacker's user account. 5) Once the session is updated with these escalated privileges, the attacker can access restricted administrative endpoints, modify store settings, or access sensitive customer information.\nThe lack of strict server-side verification means that the application trusts the user-supplied data in the request context regarding their intended role or permission level. This failure allows the attacker to bypass the Principle of Least Privilege. Post-exploitation, the impact is severe: the adversary inherits the full scope of the elevated role, which may include the ability to execute arbitrary commands if administrative dashboard access is achieved, or the modification of payment gateway configurations, leading to financial fraud.\nThis vulnerability does not appear to require interaction with other third-party plugins, as it is self-contained within the WooCommerce framework, highlighting a systemic flaw in how the plugin handles session authorization and role modification requests during the specified version window."
}