Impact
The Custom Fields Account Registration for WooCommerce plugin before version 1.4 fails to restrict its custom registration fields from writing to the user capabilities meta key on sites that use a non‑default database table prefix. As a result, an unauthenticated user who registers an account through the custom form can be granted the administrator role when a field configured to match a capability name is included. This flaw is identified as a CWE‑269: Improper Restriction of Operations within the Bounds of a User's Privileges.
Affected Systems
Vulnerable sites are those running the Custom Fields Account Registration for WooCommerce WordPress plugin with a version prior to 1.4 and that use a non‑default database table prefix. No additional product or version qualifiers are mentioned in the advisory.
Risk and Exploitability
The vulnerability has a CVSS score of 8.1, indicating high severity, and it is not listed in the CISA KEV catalog. The EPSS score is < 1%, indicating a very low but nonzero probability of exploitation. Based on the description, the likely attack vector is a web‑based form submission to the plugin’s registration endpoint, requiring only unauthenticated access to create an account. An attacker can craft the appropriate custom field to assign themselves the administrator privilege, elevating their access to system‑wide control.
OpenCVE Enrichment