CVE-2026-12144
saadiqbal · Wholesale for WooCommerce
The Wholesale for WooCommerce plugin for WordPress is vulnerable to improper privilege management, allowing an authenticated attacker to escalate privileges.
Executive summary
A privilege escalation vulnerability in the Wholesale for WooCommerce WordPress plugin allows authenticated users to gain unauthorized administrative access.
Vulnerability
This is a privilege management flaw (CWE-269) within the plugin's request handling logic. The vulnerability requires the attacker to be authenticated with low privileges to trigger the escalation.
Business impact
Successful exploitation allows an attacker to elevate their privileges to an administrative level. This compromise leads to full control over the WordPress installation, potentially resulting in data exfiltration, unauthorized content modification, or complete system takeover. The high CVSS score of 8.8 reflects the significant impact on system integrity and confidentiality.
Remediation
Immediate Action: There is currently no patched version available. Users should deactivate and remove the Wholesale for WooCommerce plugin until a security update is released by the vendor.
Proactive Monitoring: Review WordPress user account activity logs for unauthorized changes to administrative roles or suspicious user creation events.
Compensating Controls: Implement a Web Application Firewall (WAF) with rules configured to block suspicious requests directed at wholesale functionality, though total protection cannot be guaranteed without a patch.
Exploitation status
Public Exploit Available: No confirmed public exploit is available in the provided data.
Analyst recommendation
Given the severity of the privilege escalation, administrators must treat this as a critical risk. Since no patch is available, the only effective mitigation is the immediate removal of the vulnerable plugin to prevent unauthorized access to the site's administrative functions.