CVE-2026-27542

Rymera Web Co Pty Ltd · Woocommerce Wholesale Lead Capture

The Woocommerce Wholesale Lead Capture plugin is vulnerable to incorrect privilege assignment, which allows attackers to escalate their privileges within the WordPress environment.

Executive summary

A critical privilege escalation vulnerability in the Woocommerce Wholesale Lead Capture plugin allows users to gain unauthorized elevated permissions, potentially compromising the entire WordPress site.

Vulnerability

The plugin contains an "Incorrect Privilege Assignment" flaw. This typically occurs when a plugin fails to properly validate user roles during registration or profile updates, allowing a standard user to assign themselves administrative or other high-level privileges.

Business impact

Successful exploitation allows an attacker to take full control of the WordPress site, leading to data breaches, site defacement, or the installation of malware. The CVSS score of 9.8 reflects the extreme severity of allowing an unprivileged user to become an administrator, resulting in a total loss of confidentiality, integrity, and availability.

Remediation

Immediate Action: Update the Woocommerce Wholesale Lead Capture plugin to version 2.0.3.2 or the latest version available from the vendor.

Proactive Monitoring: Audit WordPress user accounts for any unauthorized changes to user roles, particularly new administrator accounts created through the wholesale lead capture forms.

Compensating Controls: Implement a "Least Privilege" model and use security plugins that alert on any changes to the administrator user group.

Exploitation status

Public Exploit Available: false

Analyst recommendation

This vulnerability poses a critical threat to site integrity. Organizations must apply the latest security updates for the Woocommerce Wholesale Lead Capture plugin immediately to prevent unauthorized users from gaining administrative control.