CVE-2025-49924

7.3

Josh Kohlbach · Wholesale Suite (woocommerce-wholesale-prices)

A privilege escalation vulnerability in the Josh Kohlbach Wholesale Suite plugin allows an authenticated administrator to perform unauthorized actions due to incorrect privilege assignment.

Executive summary

A critical privilege escalation vulnerability in the Josh Kohlbach Wholesale Suite plugin for WordPress poses a significant risk of unauthorized administrative access.

Vulnerability

The flaw is categorized as an Incorrect Privilege Assignment (CWE-266). It requires high-level administrative authentication to trigger, allowing an attacker to escalate privileges beyond their assigned scope.

Business impact

Successful exploitation of this vulnerability could allow an attacker to gain elevated administrative control over the affected WordPress environment. Given the CVSS score of 7.3, this represents a high-severity risk that could lead to full site compromise, unauthorized data access, and the potential for persistent backdoors. Organizations relying on this plugin for e-commerce operations face significant operational and reputational risk if the platform is compromised.

Remediation

Immediate Action: Administrators should monitor the vendor website for the release of a patched version and apply it immediately upon availability.

Proactive Monitoring: Review WordPress user account activity logs for anomalous privilege modifications or unexpected administrative actions performed by existing accounts.

Compensating Controls: Ensure that strict access control lists are in place and consider utilizing a Web Application Firewall (WAF) to monitor for suspicious requests directed at the plugin administrative endpoints.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

The risk posed by privilege escalation within an e-commerce suite is severe, as it permits lateral movement and deep system control. IT teams must prioritize the remediation of this plugin as soon as a fix is issued by the vendor. Until then, limit administrative access to the WordPress dashboard to only the most essential personnel to reduce the attack surface.

More Josh Kohlbach CVEs

Sources

Originally found and disclosed by Phat RiO | Patchstack Bug Bounty Program, per the CVE Program record.