PT-2026-64836 · WordPress · Custom Fields Account Registration For Woocommerce
CVE-2026-13152
·
Published
2026-07-27
·
Updated
2026-07-27
CVSS v3.1
8.1
High
| Vector | AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Custom Fields Account Registration For Woocommerce WordPress plugin versions prior to 1.4
Description
An issue exists where the plugin fails to prevent custom registration fields from writing to the user capabilities meta key on sites utilizing a non-default database table prefix. This allows an unauthenticated user to be granted the administrator role during account registration if a field with a corresponding name has been configured.
Recommendations
Update the plugin to version 1.4 or later.
Exploit
Fix
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Custom Fields Account Registration For Woocommerce