THREATOPS
THREAT OPSThreat News › [NVD] CVE-2026-15369 (CRITICAL 9.8) — The Custom User Registration Fields for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.3. This is due to the plugin accepting an attacker-controlled afreg_select_user_role value from the unauthenticated WooCommerce Sto

[NVD] CVE-2026-15369 (CRITICAL 9.8) — The Custom User Registration Fields for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.3. This is due to the plugin accepting an attacker-controlled afreg_select_user_role value from the unauthenticated WooCommerce Sto

mednvdPublished 2026-08-29

CVE-2026-15369 CVSS: 9.8 CRITICAL Published: 2026-08-29T20:16:31.840

The Custom User Registration Fields for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.3. This is due to the plugin accepting an attacker-controlled afreg_select_user_role value from the unauthenticated WooCommerce Store API /wc/store/v1/checkout request in the af_reg

Indicators of compromise

Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-15369