External risk intelligence

WooCommerce Designer Pro Subscriber RCE Vulnerability.

CVE advisorySeverity: CRITICAL (CVSS 9.9)

CVE-2026-32568

The vulnerability affects a WooCommerce plugin, which is a component of web-based e-commerce storefronts. These applications are designed to be public-facing web services, making the underlying plugin code directly accessible to external users over the internet as part of the standard deployment pattern for online stores.

Code Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A critical vulnerability has been identified in a WooCommerce plugin, potentially allowing unauthorized code execution. This type of issue could have significant implications for e-commerce platforms that utilize this specific plugin, by enabling malicious actors to compromise the integrity and availability of online stores. The main concern at this stage is to confirm whether this plugin is in use and assess any potential exposure.

  • Plugin allows attackers to run code.
  • Critical flaw impacts e-commerce stores.
  • Confirm use and assess potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker with low-privileged access to a WooCommerce online store can execute arbitrary code on the server by interacting with a feature within the WooCommerce Designer Pro plugin. This could allow them to take control of the e-commerce site and its data.

  • Requires low-privileged access to the store.
  • Triggers code execution via the plugin feature.
  • Allows full system control and data compromise.

Live Threat

Current exploitation, exposure, and threat context

This vulnerability in a WooCommerce plugin could allow an authenticated subscriber to execute arbitrary code on the server. This could potentially impact the integrity and availability of the e-commerce store, affecting its services and sensitive system data.

  • Server-side code execution.
  • Attacker sends malicious code via plugin.
  • Compromised e-commerce site operations.

Operational Fix

Recommended remediation, mitigation, and detection steps

Application owners and platform teams are most likely responsible for addressing this vulnerability, as it impacts a WooCommerce plugin. The first practical step is to identify all WooCommerce instances, determine their exposure and business criticality, and then assign ownership for remediation planning.

  • Identify affected WooCommerce instances.
  • Verify plugin reachability and business criticality.
  • Plan remediation based on assigned ownership.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is WooCommerce Designer Pro and why do stores use it?

WooCommerce Designer Pro is an extension plugin for WordPress e-commerce sites. Store owners install it to add specialized design, layout, or customization tools to their digital storefronts, allowing them to manage the visual appearance of their products and checkout experiences more easily within the WooCommerce ecosystem.

How does CWE-94 relate to CVE-2026-32568?

This CVE involves a weakness called Improper Control of Generation of Code, or CWE-94. In plain terms, it means the plugin fails to properly filter or restrict commands sent to it. Because of this, an attacker can input their own malicious commands, which the server then mistakenly runs as if they were legitimate instructions, leading to remote code execution.

Do I need administrator access to trigger this vulnerability?

No, you do not need administrative rights. The vulnerability is triggered by an attacker who has at least a low-privileged account, such as a standard subscriber account on the site. Simply browsing the site as a guest or unauthenticated user will not trigger the bug; the attacker must have a registered account to interact with the vulnerable plugin feature.

Is my site at risk if it uses WooCommerce Designer Pro?

According to Halo Surface Signal, this plugin is part of the standard deployment pattern for web-based e-commerce storefronts. Since these sites are designed to be public-facing and reachable over the internet, the plugin code is inherently accessible to external users, increasing the likelihood that your instance could be targeted.

When should I begin remediation for CVE-2026-32568?

You should prioritize this immediately by first identifying every instance of WooCommerce running this plugin in your environment. Once you have a list of affected sites, determine which ones handle the most sensitive data or business traffic, assign an owner to each, and create a plan to update or remove the plugin.

References