{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/vendors/rymera-web-co/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-12144"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Wholesale for WooCommerce plugin (up to 2.0.5)"],"_cs_severities":["critical"],"_cs_tags":["wordpress","plugin","privilege-escalation","web-vulnerability"],"_cs_type":"advisory","_cs_vendors":["Rymera Web Co"],"content_html":"\u003cp\u003eThe Wholesale for WooCommerce plugin for WordPress, in all versions up to and including 2.0.5, contains a critical privilege escalation vulnerability, tracked as CVE-2026-12144. This flaw arises from inadequate validation within the \u003ccode\u003esave_requests_meta()\u003c/code\u003e function, which only applies \u003ccode\u003esanitize_text_field()\u003c/code\u003e to the \u003ccode\u003euser_role_set\u003c/code\u003e POST parameter before directly passing it to \u003ccode\u003eWP_User::add_role()\u003c/code\u003e. Crucially, the function lacks both an allowlist to restrict permissible roles and a proper capability check, such as \u003ccode\u003ecurrent_user_can('promote_users')\u003c/code\u003e. This oversight enables authenticated attackers with at least author-level privileges to escalate their access to administrator by submitting a crafted request where the \u003ccode\u003euser_role_set\u003c/code\u003e parameter is set to \u0026quot;administrator\u0026quot;. The function is protected by a \u003ccode\u003erequest_user_role_nonce\u003c/code\u003e, but any author-level user who has published a \u003ccode\u003ewwp_requests\u003c/code\u003e post (e.g., via the wholesale registration form) can easily obtain this nonce from the post edit screen, making exploitation straightforward for an attacker who has gained a low-level authenticated session.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAn authenticated attacker obtains author-level access or higher on a WordPress site running the vulnerable Wholesale for WooCommerce plugin.\u003c/li\u003e\n\u003cli\u003eThe attacker identifies or creates a \u003ccode\u003ewwp_requests\u003c/code\u003e custom post type entry, which is typically created via the plugin's wholesale registration form.\u003c/li\u003e\n\u003cli\u003eThe attacker accesses the WordPress admin interface to view the edit screen for a \u003ccode\u003ewwp_requests\u003c/code\u003e post.\u003c/li\u003e\n\u003cli\u003eFrom the post edit screen, the attacker extracts the valid \u003ccode\u003erequest_user_role_nonce\u003c/code\u003e value, which is rendered within the meta box.\u003c/li\u003e\n\u003cli\u003eThe attacker crafts an HTTP POST request targeting the \u003ccode\u003esave_requests_meta()\u003c/code\u003e function, typically invoked during the saving of the \u003ccode\u003ewwp_requests\u003c/code\u003e post.\u003c/li\u003e\n\u003cli\u003eThe crafted request includes the obtained \u003ccode\u003erequest_user_role_nonce\u003c/code\u003e for validation and sets the \u003ccode\u003euser_role_set\u003c/code\u003e POST parameter to \u0026quot;administrator\u0026quot;.\u003c/li\u003e\n\u003cli\u003eThe vulnerable \u003ccode\u003esave_requests_meta()\u003c/code\u003e function processes the request, passes the \u0026quot;administrator\u0026quot; role value to \u003ccode\u003eWP_User::add_role()\u003c/code\u003e without sufficient validation or capability checks.\u003c/li\u003e\n\u003cli\u003eThe \u003ccode\u003eWP_User::add_role()\u003c/code\u003e function successfully assigns the administrator role to the attacker's user account, completing the privilege escalation.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of CVE-2026-12144 allows an authenticated attacker, even with low-level privileges such as author, to gain full administrator control over the affected WordPress site. This leads to complete compromise of the website, including the ability to manipulate all content, install malicious plugins, alter themes, modify site settings, steal sensitive data, and potentially pivot to other systems within the hosting environment. The widespread use of WordPress and the WooCommerce ecosystem implies a broad potential victim base for this type of vulnerability, particularly e-commerce sites relying on the Wholesale for WooCommerce plugin.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eImmediately update the Wholesale for WooCommerce plugin to a version patched against CVE-2026-12144.\u003c/li\u003e\n\u003cli\u003eRegularly review WordPress user accounts and their assigned roles for any unauthorized changes.\u003c/li\u003e\n\u003cli\u003eMonitor WordPress application logs and security plugin logs for suspicious POST requests to administrative endpoints, especially those involving user role modifications.\u003c/li\u003e\n\u003cli\u003eEnsure robust web application firewall (WAF) rules are in place to help detect and block anomalous requests that might indicate exploitation attempts, particularly those targeting \u003ccode\u003ewp-admin/post.php\u003c/code\u003e or similar endpoints with unusual parameters.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-07-29T02:18:38Z","date_published":"2026-07-29T02:18:38Z","id":"https://feed.craftedsignal.io/briefs/2026-07-wordpress-wholesale-privesc/","summary":"The Wholesale for WooCommerce plugin for WordPress is vulnerable to privilege escalation due to insufficient validation and capability checks in `save_requests_meta()` function, allowing authenticated attackers with author-level access or higher to escalate their privileges to administrator by supplying 'administrator' as the `user_role_set` value in a crafted request.","title":"WordPress Wholesale for WooCommerce Plugin Privilege Escalation (CVE-2026-12144)","url":"https://feed.craftedsignal.io/briefs/2026-07-wordpress-wholesale-privesc/"}],"language":"en","title":"CraftedSignal Threat Feed - Rymera Web Co","version":"https://jsonfeed.org/version/1.1"}