Description
Incorrect Privilege Assignment vulnerability in Automattic WooCommerce woocommerce allows Privilege Escalation.This issue affects WooCommerce: from 9.8.0 through 11.1.2.
Published: 2026-10-10
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: Privilege Escalation
Action: Patch Immediately
AI Analysis

Impact

A flaw in the Automattic WooCommerce plugin caused incorrect privilege assignment, allowing users with certain roles to gain elevated permissions beyond their intended level. This can let an attacker modify store settings, view sensitive data, or perform actions normally restricted to administrators. The weakness is classified as CWE‑266. Because elevated privileges can be achieved, the attacker can compromise the confidentiality, integrity, and availability of the e‑commerce site.

Affected Systems

WordPress sites running the WooCommerce plugin with any version from 9.8.0 up to and including 11.1.2 are affected. This includes the standard default installation as well as any custom configurations that install those legacy plugin versions.

Risk and Exploitability

The CVSS score of 7.2 indicates high severity. EPSS data is not available, and the vulnerability is not currently listed in the CISA KEV catalog. The most likely attack vector requires authenticated access with a role that possesses default shop‑manager capabilities; the attacker then exploits the faulty privilege assignment logic to elevate privileges. Once elevated, the attacker can exploit the site’s full administrative functionality. The lack of remote exploitation data means that immediate patching is recommended without waiting for any exploit activity to surface.

Generated by OpenCVE AI on October 10, 2026 at 18:23 UTC.

Remediation

Vendor Solution

Update the WordPress WooCommerce plugin to the latest available version (at least 11.2.0).


OpenCVE Recommended Actions

  • Immediately update WooCommerce to the latest release (11.2.0 or newer).
  • After updating, audit user roles to confirm no shop‑manager role retains administrative permissions.
  • Restrict or remove any custom plugins, extensions, or role‑modification code that may re‑enable the flawed privilege assignment.

Generated by OpenCVE AI on October 10, 2026 at 18:23 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 10 Oct 2026 17:15:00 +0000

Type Values Removed Values Added
Description Incorrect Privilege Assignment vulnerability in Automattic WooCommerce woocommerce allows Privilege Escalation.This issue affects WooCommerce: from 9.8.0 through 11.1.2.
Title WordPress WooCommerce plugin 9.8.0-11.1.2 - Shop Manager+ Privilege Escalation vulnerability
Weaknesses CWE-266
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-10-10T17:00:10.174Z

Reserved: 2026-10-07T00:21:31.996Z

Link: CVE-2026-106608

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-10T17:17:00.190

Modified: 2026-10-10T17:17:00.190

Link: CVE-2026-106608

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-10T18:30:08Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment