What the vulnerability does
01Description
The WooCommerce Customers Manager plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the ajax_assign_new_roles() function in all versions up to, and including, 31.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to elevate their privileges to that of an administrator.
Explanation of Vulnerability in Simple Terms
02Summary
WooCommerce Customers Manager versions 31.3 and earlier contain a privilege management flaw that allows authenticated users with low-level access to perform actions reserved for administrators. An attacker with a standard user account can read sensitive data, modify site content, and disrupt service without requiring additional interaction or elevated permissions.
What an attacker can do
03Attacker Capabilities
Read sensitive data, modify site content, and disrupt service using a low-privilege user account.
Potential impact on your site
04Site Impact
Any registered user can escalate their capabilities to perform admin-level actions on your WooCommerce store.
Conditions required to exploit
05Prerequisites
Attacker must have a valid low-privilege user account on the site.
Key dates
06Disclosure timeline
February 1, 2025
CVE published
April 8, 2026
Record updated