SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-12144

HIGH · CVSS 8.8 EPSS 0.36%

Source: NVD + CISA KEV + EPSS · Published 2026-07-29 · Last synced 2026-08-28

CyberRota Analysis

AI-Generated

The Wholesale for WooCommerce plugin for WordPress is vulnerable to privilege escalation, allowing authenticated users with author-level access to elevate their privileges to administrator by manipulating the `user_role_set` parameter in a crafted request. This vulnerability arises from insufficient validation and capability checks in the `save_requests_meta()` function, which could be exploited by attackers to gain unauthorized access. WordPress site administrators and developers using this plugin should prioritize patching to mitigate the risk of unauthorized privilege escalation.

CVE
CVE-2026-12144
Severity
HIGH
CVSS
8.8
EPSS
0.36%
WordPress

Original NVD Description

The Wholesale for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.5. This is due to the `save_requests_meta()` function applying only `sanitize_text_field()` to the `user_role_set` POST parameter before passing it directly to `WP_User::add_role()`, with no allowlist validation against permitted wholesale roles and no capability check such as `current_user_can('promote_users')` or `current_user_can('manage_options')`. This makes it possible for authenticated attackers with author-level access and above to escalate their privileges to administrator by supplying `administrator` as the `user_role_set` value in a crafted request. The function is gated only by a nonce (`request_user_role_nonce`) that is rendered in the meta box on the `wwp_requests` post edit screen; because the post type is registered with `capability_type => 'post'`, any author-level user who has authored a `wwp_requests` post — such as one created via the wholesale registration form — can access this nonce and submit the role-assignment request.