PT-2026-72876 · WordPress · Wholesale Market
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Wholesale Market versions prior to 2.2.3
Description
The Wholesale Market plugin for WordPress allows authenticated users with Subscriber-level access or higher to escalate their privileges to Administrator. This occurs when the site administrator has enabled the 'Assigning requested role directly' option. The issue exists in the
ced wholesale request send AJAX action, where the ced wholesale request send callback() handler fails to restrict the role required POST parameter to a predefined list of wholesale roles before passing it to the WP User::add role() function. The handler only verifies a nonce and a positive user ID, both of which are accessible to authenticated users.Recommendations
Update to a version newer than 2.2.2.
Disable the 'Assigning requested role directly' option to prevent unauthorized privilege escalation.
Fix
LPE
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Wholesale Market