CVE Vulnerabilities

CVE-2026-12144

Improper Privilege Management

Published: Jul 29, 2026 | Modified: Jul 29, 2026
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

The Wholesale for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.5. This is due to the save_requests_meta() function applying only sanitize_text_field() to the user_role_set POST parameter before passing it directly to WP_User::add_role(), with no allowlist validation against permitted wholesale roles and no capability check such as current_user_can(promote_users) or current_user_can(manage_options). This makes it possible for authenticated attackers with author-level access and above to escalate their privileges to administrator by supplying administrator as the user_role_set value in a crafted request. The function is gated only by a nonce (request_user_role_nonce) that is rendered in the meta box on the wwp_requests post edit screen; because the post type is registered with capability_type => post, any author-level user who has authored a wwp_requests post — such as one created via the wholesale registration form — can access this nonce and submit the role-assignment request.

Weakness

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Potential Mitigations

References