CVE-2026-14279
8.8CedCommerce · Wholesale Market
The Wholesale Market plugin for WordPress contains a privilege escalation vulnerability that allows authenticated users to gain unauthorized administrative access.
Executive summary
A privilege escalation vulnerability in the Wholesale Market plugin for WordPress allows low-privileged users to gain unauthorized administrative control over the site.
Vulnerability
This vulnerability (CWE-269) involves improper privilege management within the plugin, allowing an authenticated user with low privileges to escalate their authority to that of an administrator.
Business impact
A successful exploit grants an attacker full control over the WordPress installation. This leads to complete system compromise, including the ability to install malicious code, modify site content, or access sensitive user and transaction data, justifying the high CVSS score of 8.8.
Remediation
Immediate Action: Since no patch is currently available, administrators should immediately deactivate and uninstall the Wholesale Market plugin until a secure version is released.
Proactive Monitoring: Monitor user account creation and privilege modification logs for suspicious activity or unauthorized elevation of user roles.
Compensating Controls: Use a Web Application Firewall (WAF) to restrict access to sensitive administrative endpoints and monitor for unusual requests from low-privileged user accounts.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the high impact of privilege escalation and the current absence of a vendor patch, immediate deactivation of the plugin is the only effective way to eliminate the risk of total system compromise.