PT-2026-65676 · WordPress · Wholesale For Woocommerce
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Wholesale for WooCommerce versions prior to 2.0.6
Description
Authenticated users with author-level access and above can escalate their privileges to administrator. The issue exists in the
save requests meta() function, which fails to perform capability checks, such as current user can('promote users') or current user can('manage options'), and lacks allowlist validation for the user role set POST parameter. Because the wwp requests post type is registered with capability type => 'post', authors who have created a request can access the request user role nonce nonce and submit a crafted request with the user role set variable set to administrator to gain full administrative control.Recommendations
Update Wholesale for WooCommerce to version 2.0.6 or later.
Fix
LPE
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wholesale For Woocommerce