Executive brief
A vulnerability in the Registration Form for WooCommerce plugin for WordPress allows unauthorized users to gain administrative control over a website. This plugin is used to customize user registration for online stores. An attacker could exploit this flaw to take over the site, potentially leading to the theft of customer data, service disruption, or complete site defacement.
Technical details
The Registration Form for WooCommerce plugin for WordPress (versions <= 1.0.9) is vulnerable to unauthenticated privilege escalation due to incorrect privilege assignment (CWE-266) within its registration handling logic. A remote, unauthenticated attacker can exploit this flaw to register an account with elevated privileges, such as Administrator, without any prior authentication or user interaction. This allows for a complete compromise of the WordPress instance. The issue is resolved in version 1.1.0.
Affected products
- ThemeGrill Registration Form for WooCommerce <= 1.0.9
Timeline
- 2026-05-27: other: Reported by ParkHyunWoo
- 2026-06-16: advisory: Patchstack advisory published
- 2026-06-17: disclosed: NVD publication date