CVE-2026-12736

WordPress · WPify Woo – Withdrawal, CRN/VAT, QR payments, Heureka and more for WooCommerce

The WPify Woo plugin for WordPress contains an improper privilege management vulnerability, allowing authenticated attackers with high privileges to escalate their access level.

Executive summary

A privilege escalation vulnerability in the WPify Woo plugin for WordPress, rated as High severity, poses a significant risk of full system compromise.

Vulnerability

This vulnerability is categorized as CWE-269 (Improper Privilege Management). It requires the attacker to be authenticated with high privileges to exploit the flaw, which allows for unauthorized elevation of access within the WordPress environment.

Business impact

Successful exploitation of this flaw could allow an attacker to gain administrative control over the WordPress installation. Given the CVSS score of 8.0, this represents a high-risk scenario that could lead to complete data compromise, unauthorized modification of site content, and potential service disruption.

Remediation

Immediate Action: Update the WPify Woo plugin to version 5.4.17 or later immediately.

Proactive Monitoring: Review WordPress administrative logs for unusual user account creation or modification activities that deviate from standard operational patterns.

Compensating Controls: Ensure that access to the WordPress administrative dashboard is restricted to trusted IP addresses via a Web Application Firewall (WAF) to limit the exposure of the vulnerable administrative functions.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

This vulnerability presents a clear risk to the integrity and confidentiality of the WordPress platform. Administrators should prioritize updating the plugin to the patched version as soon as possible to neutralize the threat of privilege escalation.