← Back to feed
Vulnerabilities & PatchesEmerging1 sourceAug 29, 2026 · 20:16via CVEFeed

CVE-2026-15369 - Custom User Registration Fields for WooCommerce = 2.2.3 - Unauthenticated Privilege Escalation via 'afreg_select_user_role' Parameter in Store API Checkout

Brief

CVE ID : CVE-2026-15369

Published : Aug. 29, 2026, 8:16 p. m.

  • 58 minutes ago

Description : The Custom User Registration Fields for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.

  • 3.

This is due to the plugin accepting an attacker-controlled afreg_select_user_role value from the unauthenticated WooCommerce Store API /wc/store/v1/checkout request in the af_reg_checkout_data_to_order_meta_data_block() function, persisting it in order meta, and then passing it directly to WP_User::add_role() in the af_reg_custom_order_processing_function() function (hooked to woocommerce_thankyou) without validating against the plugin's admin-configured allowed role list.

Read more on CVEFeed