{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/wholesale-market/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-14279"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Wholesale Market"],"_cs_severities":["high"],"_cs_tags":["wordpress","privilege-escalation","web-application"],"_cs_type":"advisory","_cs_vendors":["WordPress"],"content_html":"\u003cp\u003eThe Wholesale Market plugin for WordPress, in versions up to and including 2.2.2, is susceptible to a privilege escalation vulnerability within the ced_wholesale_request_send AJAX handler. The vulnerability exists because the ced_wholesale_request_send_callback function performs inadequate security validation. Specifically, it only verifies a nonce that is exposed to any authenticated user via wp_localize_script and confirms a positive user ID. Crucially, the function fails to validate the role_required POST parameter against a secure allowlist, instead passing it directly to the WP_User::add_role() function. If the 'Assigning requested role directly' option is enabled in the plugin configuration, any authenticated attacker with at least Subscriber-level access can manipulate this parameter to assign themselves the Administrator role. This issue represents a significant risk to WordPress installations utilizing this plugin for B2B wholesale management.\u003c/p\u003e\n","date_modified":"2026-08-15T08:17:10Z","date_published":"2026-08-15T08:17:10Z","id":"https://feed.craftedsignal.io/briefs/2026-08-wholesale-market-priv-esc/","summary":"The Wholesale Market plugin for WordPress up to version 2.2.2 contains a privilege escalation vulnerability via the ced_wholesale_request_send AJAX action that allows authenticated users to elevate to Administrator.","title":"Privilege Escalation in Wholesale Market WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-08-wholesale-market-priv-esc/"}],"language":"en","title":"CraftedSignal Threat Feed - Wholesale Market","version":"https://jsonfeed.org/version/1.1"}