Back to overview

CVE-2026-13152

Description
The Custom Fields Account Registration For Woocommerce WordPress plugin before 1.4 does not prevent its custom registration fields from writing to the user capabilities meta key on sites that use a non-default database table prefix, so an unauthenticated user who registers an account can be granted the administrator role when a correspondingly named field has been configured.

Metadata

CVE ID
CVE-2026-13152
State
PUBLISHED
Assigner
WPScan
Reserved
2026-06-24 11:18 UTC
Published
2026-07-27 06:00 UTC
Last updated
2026-07-27 06:00 UTC
Vendor / Product
Unknown / Custom Fields Account Registration For Woocommerce
Sources
cve.org  ·  NVD

Severity & Metrics

No CVSS data available.

Affected products (1)
VendorProductPlatformVersions
Unknown Custom Fields Account Registration For Woocommerce 0 < 1.4
Weakness (CWE)
CWESourceDescription
cna CWE-269 Improper Privilege Management
Back to overview