Impact
The vulnerability resides in the WooCommerce Registration Form WordPress plugin versions prior to 1.1.3, which fails to verify that the registration form being referenced is legitimate. An attacker who can create a post—an ability granted to users with Contributor role or higher—can supply an arbitrary post ID that the plugin reads to determine the allowed role for new users. This bypasses the intended role permissions and allows the attacker to register a new account with any role, including Administrator, thus compromising full site control. The weakness can be exploited simply by creating a post with the chosen role and then submitting a registration form that references that post, without needing any additional privileges beyond those required to publish a post.
Affected Systems
Any WordPress site using the WooCommerce Registration Form plugin version 1.1.0 to 1.1.2 is affected. The vulnerability has been identified on all installations that have not updated to 1.1.3 or later, regardless of other configurations. The weakness is independent of the site’s theme or other plugins, but requires that the attacker can create a post with Contributor or higher capability. No specific operating system or server platform is required for exploitation.
Risk and Exploitability
Because the vulnerability grants the attacker full administrative privileges once exploited, the risk is extremely high. The attack requires only the ability to create a post, a capability commonly available to contributors in many WordPress sites. No public exploits are reported and the EPSS score is not available, yet the lack of a requirement for advanced skills or zero-day conditions suggests that opportunistic attackers could readily exploit the flaw. The vulnerability is not listed in the CISA KEV catalog and no official exploitation tool is known, but the potential impact justifies a high severity assessment.
OpenCVE Enrichment