Skip to main content
QUIETLYTIC
Vulnerability

Custom User Registration Fields for WooCommerce Privilege Escalation (CVE-2026-15369)

CVE-2026-15369 is a CVSS 9.8 flaw in a WooCommerce checkout plugin allowing unauthenticated Administrator account creation, reported exploited by VulnCheck.

CVE-2026-15369
Threat Level
CRITICAL
CVSS
9.8
Status
Active Exploitation
Confidence
Medium
Affected Products
Custom User Registration Fields for WooCommerce, Addify Custom User Registration Fields for WooCommerce (through 2.2.3)

CVE-2026-15369 carries a CVSS 3.1 base score of 9.8 against Custom User Registration Fields for WooCommerce, a WordPress plugin published by Addify that adds custom fields to WooCommerce’s checkout and account-registration flow. NVD classifies it as CWE-269 (Improper Privilege Management) and describes a path to unauthenticated Administrator account creation in versions up to and including 2.2.3. VulnCheck’s KEV feed reports the CVE as exploited, dated August 31, 2026.

That exploitation report is single-sourced. CISA has not added CVE-2026-15369 to its Known Exploited Vulnerabilities catalog as of our most recent CISA KEV ingestion on September 19, 2026. VulnCheck’s catalog admits vendor and researcher exploitation reporting on broader criteria than CISA’s own listing process has accepted; no Binding Operational Directive 26-04 remediation obligation follows from a VulnCheck-only listing.

What the flaw is

NVD’s description names the exact defect chain: the plugin accepts an attacker-controlled afreg_select_user_role value from WooCommerce’s own unauthenticated Store API checkout request, stores that value in order metadata, and later passes it directly to WordPress’s WP_User::add_role() function without checking it against the plugin’s own admin-configured list of allowed roles. Because the Store API checkout endpoint requires no authentication by design — that is how WooCommerce lets shoppers check out as guests — an attacker can create an account during checkout while specifying administrator, or any other role slug, as the desired role.

NVD states one precondition explicitly: exploitation requires the plugin’s “User Role Selection” setting to be enabled. That is an admin-configured option, not the plugin’s state out of the box, so exposure depends on how a given store has configured the plugin rather than on installation alone.

Evidence and confidence

  • Medium confidence — the CVSS 9.8 score, the vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), the CWE-269 classification, the full defect chain (the vulnerable API parameter, the unvalidated role assignment, and the “User Role Selection” precondition), and the 2.2.3 affected-version ceiling all trace to NVD alone. The exploitation report traces to VulnCheck KEV alone.
  • Unknown-leaning — exploitation probability. FIRST’s EPSS model scores this CVE 0.00397, 33.5th percentile as of our ingestion — below the midpoint of the broader EPSS population.

No field is in conflict between our two sources. Our data carries no fixed-version field; NVD names 2.2.3 only as the affected ceiling.

Why this matters

This vulnerability sits in a checkout flow, which is exactly the surface a WooCommerce store cannot disable without disabling the store itself — unlike a comment section or an optional feature, checkout is core functionality that stays reachable to any visitor. Combined with an admin-configured precondition rather than a default-off one, this is a case where the vulnerability’s real-world exposure depends heavily on store-specific configuration that a generic scan or version check alone won’t reveal.

The severity case for upgrading does not depend on the VulnCheck exploitation report: NVD’s own description states unauthenticated Administrator account creation as the outcome, under the stated precondition, which is sufficient grounds to patch or disable the “User Role Selection” setting immediately regardless of catalog status.

Frequently Asked Questions

What is CVE-2026-15369? A CVSS 9.8 privilege escalation vulnerability (CWE-269) in Custom User Registration Fields for WooCommerce, a WordPress plugin, that NVD states allows unauthenticated attackers to create Administrator accounts via a modified checkout request, in versions through 2.2.3.

Is CVE-2026-15369 being actively exploited? VulnCheck’s KEV feed reports it exploited, dated August 31, 2026. That report is single-sourced; CISA has not listed this CVE as of our September 19, 2026 ingestion, and we have no independent corroboration.

Do I need a specific setting enabled for my store to be at risk? Yes. NVD states the exploit requires the plugin’s “User Role Selection” setting to be enabled. Stores that have not enabled that setting are not exposed through this specific path.

Does this create a federal patching deadline? No. Directive 26-04 obligations follow CISA KEV listing, and this CVE is not CISA-listed.

What should I do if I can’t upgrade immediately? Disable the “User Role Selection” setting in the plugin’s configuration. NVD states this is a precondition for exploitation, so removing it closes the specific path described, though upgrading remains the complete fix once a patched version is available.


Severity, vector, weakness classification, full defect chain, and affected-version ceiling sourced from the National Vulnerability Database record for CVE-2026-15369. Exploitation status and the August 31, 2026 catalog date are reported by VulnCheck KEV, an authenticated feed with no public per-CVE page to cite. This CVE is not listed in CISA’s Known Exploited Vulnerabilities catalog as reflected in our ingestion through September 19, 2026. EPSS score and percentile from FIRST’s Exploit Prediction Scoring System. Aggregated September 20, 2026. See more vulnerability intelligence.

Report an error

Found a factual error, an outdated figure, or a broken source link? Let us know and our editorial desk will review it.


Sources & evidence

01 National Vulnerability Database (NVD)
02 VulnCheck KEV

Related intelligence


Analyst tools