CVE-2026-27542
Rymera Web Co Pty Ltd · Woocommerce Wholesale Lead Capture
The Woocommerce Wholesale Lead Capture plugin is vulnerable to incorrect privilege assignment, which allows attackers to escalate their privileges within the WordPress environment.
Executive summary
A critical privilege escalation vulnerability in the Woocommerce Wholesale Lead Capture plugin allows users to gain unauthorized elevated permissions, potentially compromising the entire WordPress site.
Vulnerability
The plugin contains an "Incorrect Privilege Assignment" flaw. This typically occurs when a plugin fails to properly validate user roles during registration or profile updates, allowing a standard user to assign themselves administrative or other high-level privileges.
Business impact
Successful exploitation allows an attacker to take full control of the WordPress site, leading to data breaches, site defacement, or the installation of malware. The CVSS score of 9.8 reflects the extreme severity of allowing an unprivileged user to become an administrator, resulting in a total loss of confidentiality, integrity, and availability.
Remediation
Immediate Action: Update the Woocommerce Wholesale Lead Capture plugin to version 2.0.3.2 or the latest version available from the vendor.
Proactive Monitoring: Audit WordPress user accounts for any unauthorized changes to user roles, particularly new administrator accounts created through the wholesale lead capture forms.
Compensating Controls: Implement a "Least Privilege" model and use security plugins that alert on any changes to the administrator user group.
Exploitation status
Public Exploit Available: false
Analyst recommendation
This vulnerability poses a critical threat to site integrity. Organizations must apply the latest security updates for the Woocommerce Wholesale Lead Capture plugin immediately to prevent unauthorized users from gaining administrative control.