CVE-2026-15369
Custom User Registration Fields for WooCommerce Privilege Escalation via Store API.
Halo Surface Signal: 5 out of 5 — more likely to be public-facing.
The Custom User Registration Fields for WooCommerce plugin contains a privilege escalation vulnerability. An unauthenticated attacker could exploit this by sending a crafted request to the WooCommerce Store API during checkout, allowing them to assign themselves an administrator role if a specific plugin setting is ena