PT-2026-64226 · WordPress · Wpify Woo

·

CVE-2026-12736

·

Published

2026-07-24

·

Updated

2026-07-24

CVSS v3.1

8.0

High

VectorAV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Wpify Woo versions prior to 5.4.17
Description The Wpify Woo plugin for WordPress allows authenticated users with Shop Manager-level access or higher to escalate their privileges to Administrator. This occurs because the SettingsApi::save option() function in the REST endpoint 'POST /wp-json/wpify-woo/v1/option' passes the option and data parameters directly to the update option() function without sanitizing the values or using an allowlist for option names. Consequently, an attacker can overwrite arbitrary WordPress options, such as modifying default role to administrator, enabling users can register, or disabling security plugins through the active plugins option.
Recommendations Update the plugin to a version later than 5.4.16. Restrict access to the 'POST /wp-json/wpify-woo/v1/option' endpoint to minimize the risk of exploitation.

Fix

LPE

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-12736

Affected Products

Wpify Woo