Impact
The vulnerability in the WooCommerce Registration Fields Plugin – Custom Signup Fields allows an attacker to incorrectly assign privileges, leading to privilege escalation. This flaw enables the attacker to elevate their permissions beyond the intended scope, potentially granting them administrative or higher access to the WordPress site.
Affected Systems
The affected product is the WooCommerce Registration Fields Plugin – Custom Signup Fields by extendons. All releases up through version 3.2.3, including earlier builds, are vulnerable.
Risk and Exploitability
With a CVSS score of 8.8, the issue is high severity. The EPSS score of less than 1% indicates a low probability of current exploitation, and it is not listed in the CISA KEV catalog. The likely attack vector is via remote web interactions, such as submitting registration requests or other publicly accessible plugin endpoints, which the vulnerable code misinterprets and grants elevated privileges.
OpenCVE Enrichment