CVE-2026-13152

Custom Fields · Custom Fields Account Registration For Woocommerce

The Custom Fields Account Registration For Woocommerce WordPress plugin contains an improper privilege management vulnerability that could allow unauthorized escalation of user account permissions.

Executive summary

An improper privilege management vulnerability in the Custom Fields Account Registration For Woocommerce plugin could allow attackers to gain unauthorized elevated access.

Vulnerability

This plugin is affected by an Improper Privilege Management flaw (CWE-269), which potentially allows for unauthorized escalation of privileges during or after the account registration process.

Business impact

A successful exploit could allow an attacker to gain higher-level privileges than intended, potentially resulting in full administrative control over the WordPress instance. With a CVSS score of 8.1, this represents a significant threat to the integrity and confidentiality of the entire site, including user data and system settings.

Remediation

Immediate Action: Update the Custom Fields Account Registration For Woocommerce plugin to version 1.4 or later immediately.

Proactive Monitoring: Audit user account creation logs and look for accounts that have been granted administrative or elevated roles without corresponding authorization.

Compensating Controls: If an update cannot be applied immediately, restrict access to the registration pages or disable account creation functionality as a temporary measure.

Exploitation status

Public Exploit Available: No (exploit_available: unknown)

Analyst recommendation

Privilege management flaws are critical security risks that can undermine the entire security model of a web application. Administrators should prioritize updating this plugin to version 1.4 to ensure that account registration processes are properly secured against escalation attempts.