THREAT OPS › Threat News › [NVD] CVE-2026-15369 (CRITICAL 9.8) — The Custom User Registration Fields for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.3. This is due to the plugin accepting an attacker-controlled afreg_select_user_role value from the unauthenticated WooCommerce Sto
[NVD] CVE-2026-15369 (CRITICAL 9.8) — The Custom User Registration Fields for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.3. This is due to the plugin accepting an attacker-controlled afreg_select_user_role value from the unauthenticated WooCommerce Sto
CVE-2026-15369 CVSS: 9.8 CRITICAL Published: 2026-08-29T20:16:31.840
The Custom User Registration Fields for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.3. This is due to the plugin accepting an attacker-controlled afreg_select_user_role value from the unauthenticated WooCommerce Store API /wc/store/v1/checkout request in the af_reg
Indicators of compromise
- CVE-2026-15369cve
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-15369