Junglewise Threat Intelligence

CVE-2026-39546: Techspawn MultiLoca privilege escalation in WordPress plugin

CVE-2026-39546 · Severity: high · CVSS 7.6 · Published 2026-06-17

Executive brief

MultiLoca is a WordPress plugin used to manage inventory across multiple physical locations for WooCommerce stores. A security flaw allows users with basic 'Subscriber' accounts to elevate their permissions, potentially gaining full administrative control over the website. This could lead to unauthorized access to customer data, site defacement, or complete service disruption.

Technical details

A privilege escalation vulnerability exists in the Techspawn MultiLoca (WooCommerce Multi Locations Inventory Management) plugin for WordPress due to incorrect privilege assignment (CWE-266). The flaw is present in versions up to and including 4.2.15. An authenticated attacker with a low-privileged account, such as a Subscriber, can exploit this vulnerability over the network without user interaction. Successful exploitation allows the attacker to escalate their privileges, potentially reaching administrative levels and gaining full control over the WordPress environment. The issue is resolved in version 4.2.16.

Affected products

  • Techspawn MultiLoca (WooCommerce Multi Locations Inventory Management) <= 4.2.15

Timeline

  • 2026-02-17: other: Vulnerability reported by Denver Jackson
  • 2026-04-08: disclosed: Initial disclosure by Patchstack
  • 2026-06-17: advisory: NVD publication date
  • 2026-04-08: patched: Patch released in version 4.2.16

References