Sceawere
Vulnerability Detail
CVE-2026-32568UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV
WooCommerce Designer Pro Subscriber RCE
Vulnerability Metadata
- Severity
- Critical
- Score / CVSS
- 9.9
- Creation Date
- 16h ago
- Vendor
- JMAPlugins
- Product
- WooCommerce Designer Pro
- Attack Type
- CWE-94 Improper Control of Generation of Code ('Code Injection')
- Vector String
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
- Attack Complexity
- LOW
Narrative and Response
Description
Subscriber Remote Code Execution (RCE) in WooCommerce Designer Pro <= 1.9.33 versions.
Executive Summary
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Technical Details
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Mitigations
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
References
Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.
Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.
Additional Metadata
{
"score": "9.9",
"pubDate": "2026-10-06T09:17:42.230Z",
"pubdate": "2026-10-06T09:17:42.230Z",
"executiveSummary": "A critical remote code execution (RCE) vulnerability exists in WooCommerce Designer Pro versions 1.9.33 and below. This security flaw allows authenticated users with low privileges, specifically the 'subscriber' role, to execute arbitrary code on the underlying web server.\nThe vulnerability stems from improper input validation or insecure handling of file uploads/parameters, enabling an attacker to bypass security constraints and achieve full system compromise.\nThe impact of this vulnerability is severe, as it grants unauthorized actors the ability to perform malicious actions, including data exfiltration, modification of database content, installation of web shells, and potential pivoting into the broader hosting environment.\nRisk implications are high because the exploit requires minimal privileges, making it accessible to any registered account on the WordPress site. Organizations utilizing this plugin are at significant risk of total site takeover and persistent backdoored access if left unpatched.",
"technicalDetails": "The vulnerability resides within the WooCommerce Designer Pro plugin, specifically affecting versions 1.9.33 and earlier. The root cause originates from inadequate server-side validation of user-supplied inputs, which allows a subscriber-level user to interact with internal API endpoints or file processing functions intended for administrative use.\nThe attack flow initiates when an authenticated subscriber sends a crafted request to the plugin's endpoint. Due to the lack of strict nonce verification or capability checks (e.g., current_user_can('manage_options')), the application fails to restrict access to sensitive administrative functionality. An attacker can leverage this oversight to supply malicious payload data, such as executable code or serialized objects, to vulnerable functions that do not sufficiently sanitize the input.\nIn typical exploitation scenarios, the attacker interacts with the file upload or configuration update modules of the plugin. By manipulating the request parameters, the attacker can force the application to save, rename, or include a file containing PHP code in a directory accessible to the web server. Once the malicious script is persisted on the server, the attacker triggers its execution by issuing a direct HTTP GET request to the file path.\nThe vulnerability exploits the insecure handling of dynamic file paths or parameter injection within the plugin's core logic. Because the plugin processes these requests without validating the user's role or the content of the payload, the server executes the injected code with the permissions of the web server process (e.g., www-data).\nPost-exploitation impact is extensive. Successful execution allows the attacker to establish a persistent web shell, enabling remote management of the server, unauthorized access to the WordPress database (where user credentials and configuration reside), and the ability to exfiltrate sensitive files, including wp-config.php, which contains database credentials. Furthermore, the attacker can use the compromised server as a staging point for secondary attacks on the network, potentially leading to horizontal or vertical privilege escalation."
}