CVE-2026-13152
Custom Fields · Custom Fields Account Registration For Woocommerce
The Custom Fields Account Registration For Woocommerce WordPress plugin contains an improper privilege management vulnerability that could allow unauthorized escalation of user account permissions.
Executive summary
An improper privilege management vulnerability in the Custom Fields Account Registration For Woocommerce plugin could allow attackers to gain unauthorized elevated access.
Vulnerability
This plugin is affected by an Improper Privilege Management flaw (CWE-269), which potentially allows for unauthorized escalation of privileges during or after the account registration process.
Business impact
A successful exploit could allow an attacker to gain higher-level privileges than intended, potentially resulting in full administrative control over the WordPress instance. With a CVSS score of 8.1, this represents a significant threat to the integrity and confidentiality of the entire site, including user data and system settings.
Remediation
Immediate Action: Update the Custom Fields Account Registration For Woocommerce plugin to version 1.4 or later immediately.
Proactive Monitoring: Audit user account creation logs and look for accounts that have been granted administrative or elevated roles without corresponding authorization.
Compensating Controls: If an update cannot be applied immediately, restrict access to the registration pages or disable account creation functionality as a temporary measure.
Exploitation status
Public Exploit Available: No (exploit_available: unknown)
Analyst recommendation
Privilege management flaws are critical security risks that can undermine the entire security model of a web application. Administrators should prioritize updating this plugin to version 1.4 to ensure that account registration processes are properly secured against escalation attempts.