← Back to CVE List
CVE-2026-85128Wordfence
Vulnerability Summary
The Choose User Role at Registration for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.3.2. This is due to insufficient restriction on the capabilities a user may grant themselves. This makes it possible for unauthenticated attackers to elevate their privileges beyond those intended for their role.
CVSS v3.1 Base Metrics — Score 9.8 (CRITICAL)
Attack VectorNetwork
Attack ComplexityLow
Privileges RequiredNone
User InteractionNone
ScopeUnchanged
ConfidentialityHigh
IntegrityHigh
AvailabilityHigh
Affected & Patched Versions
- Choose User Role at Registration for WooCommerce * - 1.3.2
- Choose User Role at Registration for WooCommerce 1