Description
The Registration Form for WooCommerce WordPress plugin before 1.1.3 does not validate that the form referenced during registration is a legitimate registration form, reading the permitted-role allow-list from an arbitrary attacker-controlled post instead. A user able to create a post (Contributor and above) can therefore register a new account with an arbitrary role, including Administrator, leading to full site takeover. This is an incomplete fix of CVE-2026-54807.
Published: 2026-09-10
Score: 7.2 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation through Unvalidated Role Assignment
Action: Immediate Patch
AI Analysis

Impact

The vulnerability resides in the WooCommerce Registration Form WordPress plugin versions prior to 1.1.3, which fails to verify that the registration form being referenced is legitimate. An attacker who can create a post—an ability granted to users with Contributor role or higher—can supply an arbitrary post ID that the plugin reads to determine the allowed role for new users. This bypasses the intended role permissions and allows the attacker to register a new account with any role, including Administrator, thus compromising full site control. The weakness can be exploited simply by creating a post with the chosen role and then submitting a registration form that references that post, without needing any additional privileges beyond those required to publish a post.

Affected Systems

Any WordPress site using the WooCommerce Registration Form plugin version 1.1.0 to 1.1.2 is affected. The have not updated to 1.1.3 or later, regardless of other configurations. The weakness is independent of the site’s theme or other plugins, but requires that the attacker can create a post with Contributor or higher capability. No specific operating system or server platform is required for exploitation.

Risk and Exploitability

Because the vulnerability grants the attacker full administrative privileges once exploited, the risk is extremely high. The attack requires only the ability to create a post, a capability commonly available to contributors in many WordPress sites. The EPSS score is < 1% and the CVSS score of 7.2 reflects high severity, yet no public exploits are reported, and the flaw requires only basic post‑creation privileges rather than advanced skills, suggesting opportunistic attackers could readily exploit it. The vulnerability is not listed in the CISA KEV catalog and no official exploitation tool is known, but the potential impact justifies a high severity assessment.

Generated by OpenCVE AI on September 10, 2026 at 16:00 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the WooCommerce Registration Form plugin to version 1.1.3 or later, which implements validation of the registration form reference.
  • Limit Contributor permissions to prevent non‐trusted users from creating arbitrary posts, or disable the post creation capability entirely if it is not necessary for site operation.
  • If an immediate upgrade is not feasible, enforce a custom filter or plugin that validates the role selected during registration against the site’s permitted roles, rejecting any role that is not explicitly allowed by site administrators.

Generated by OpenCVE AI on September 10, 2026 at 16:00 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 10 Sep 2026 14:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 10 Sep 2026 07:45:00 +0000

Type Values Removed Values Added
Weaknesses CWE-285

Thu, 10 Sep 2026 06:30:00 +0000

Type Values Removed Values Added
Description The Registration Form for WooCommerce WordPress plugin before 1.1.3 does not validate that the form referenced during registration is a legitimate registration form, reading the permitted-role allow-list from an arbitrary attacker-controlled post instead. A user able to create a post (Contributor and above) can therefore register a new account with an arbitrary role, including Administrator, leading to full site takeover. This is an incomplete fix of CVE-2026-54807.
Title Registration Form for WooCommerce 1.1.0 - 1.1.2 - Contributor+ Privilege Escalation via Unvalidated tgwcfb_id
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-09-10T13:11:21.791Z

Reserved: 2026-08-26T19:16:18.415Z

Link: CVE-2026-81431

cve-icon Vulnrichment

Updated: 2026-09-10T13:06:01.360Z

cve-icon NVD

Status : Deferred

Published: 2026-09-10T07:17:03.243

Modified: 2026-09-10T15:13:07.090

Link: CVE-2026-81431

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-10T16:15:06Z

Weaknesses
  • CWE-269

    Improper Privilege Management

  • CWE-285

    Improper Authorization