CVE-2025-60222

8.8

FantasticPlugins · SUMO Memberships for WooCommerce

An incorrect privilege assignment vulnerability in the SUMO Memberships for WooCommerce plugin allows authenticated users to perform unauthorized privilege escalation.

Executive summary

A high-severity privilege escalation vulnerability in the SUMO Memberships for WooCommerce plugin could allow authenticated attackers to gain elevated administrative access to the WordPress environment.

Vulnerability

The plugin suffers from an incorrect privilege assignment flaw (CWE-266), which enables an authenticated user with low privileges to escalate their access rights. This vulnerability is triggered through the plugin's membership management functionality.

Business impact

The ability for an authenticated user to escalate privileges to an administrative level poses a critical risk to the confidentiality, integrity, and availability of the entire WordPress site. With a CVSS score of 8.8, this flaw allows an attacker to take full control of the application, potentially leading to unauthorized data exfiltration, site defacement, or the installation of malicious backdoors.

Remediation

Immediate Action: Administrators must update the SUMO Memberships for WooCommerce plugin to the latest patched version available from the vendor.

Proactive Monitoring: Security teams should audit user account logs for unexpected privilege changes and monitor for suspicious administrative actions performed by non-administrator accounts.

Compensating Controls: Deploy a Web Application Firewall (WAF) with rules configured to block common privilege escalation patterns and unauthorized access attempts to plugin-specific API endpoints.

Exploitation status

Public Exploit Available: No (exploit_available: false).

Analyst recommendation

Given the severity of this privilege escalation flaw, immediate remediation is required to secure the environment. Organizations should prioritize updating the plugin and conducting a thorough review of existing user roles to ensure no unauthorized accounts have already been elevated.

Sources

Originally found and disclosed by 0xd4rk5id3 | Patchstack Bug Bounty Program, per the CVE Program record.