CVE-2026-14359 carries a CVSS 3.1 base score of 8.8 against the YITH WooCommerce Waitlist Premium plugin for WordPress. NVD classifies it as CWE-269 (Improper Privilege Management) and states the flaw affects all versions up to and including 3.35.0. VulnCheck’s KEV feed reports the CVE as exploited, dated September 9, 2026.
That exploitation report is single-sourced. CISA has not added CVE-2026-14359 to its Known Exploited Vulnerabilities catalog as of our most recent CISA KEV ingestion. VulnCheck’s catalog reports vendor and researcher exploitation observations on broader criteria than CISA’s own listing process has accepted; no Binding Operational Directive 26-04 remediation obligation follows from a VulnCheck-only listing.
What the flaw is
NVD’s description locates the flaw in the plugin’s add_user_in_waiting_list() function, registered on the wp_ajax_yith_wcwtl_add_user AJAX action. NVD states this function is missing both a capability check and a nonce verification, and uses PHP’s parse_str() and extract() functions to import attacker-controlled variables directly from the request’s params field. Those imported variables are then passed to wp_create_user() and the resulting user object’s set_role() method. NVD states this makes it possible for an authenticated attacker with Subscriber-level access — the lowest tier WordPress grants to a registered account — to create a new user and assign it the Administrator role, achieving full site takeover.
Evidence and confidence
- Medium confidence — the CVSS 8.8 score, the vector (
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H), the CWE-269 classification, and the vulnerable function all trace to NVD alone in our current ingestion, corroborated by Wordfence’s own threat intelligence entry for this CVE. The exploitation report traces to VulnCheck KEV alone. - Low-to-moderate exploitation probability — FIRST’s EPSS model scores this CVE at 0.00246, a 16.0th percentile score as of our ingestion.
No field is in conflict between our two sources.
Why this matters
This flaw requires only a Subscriber-level account — the tier WordPress grants to any visitor who can register on a site with open registration, which many WooCommerce storefronts enable by design so customers can track waitlisted products. That combination — a plugin aimed at customer-facing waitlist features, paired with a privilege-escalation path reachable by the lowest-tier account WordPress offers — is a meaningfully broader attack surface than a flaw requiring existing administrative access.
Because the exploitation report is VulnCheck-only and not yet corroborated by CISA, treat it as a credible but single-sourced signal rather than a confirmed, catalog-verified compromise campaign — still worth prioritizing given the low bar to exploit, but not (yet) the same evidentiary weight as a CISA KEV listing.
Frequently Asked Questions
What is CVE-2026-14359? A CVSS 8.8 privilege escalation vulnerability (CWE-269) in the YITH WooCommerce Waitlist Premium plugin for WordPress, affecting versions up to and including 3.35.0, allowing an authenticated Subscriber-level account to create a new Administrator user.
Is CVE-2026-14359 being actively exploited? VulnCheck’s KEV feed reports it exploited, dated September 9, 2026. That report is single-sourced; CISA has not listed this CVE in its own Known Exploited Vulnerabilities catalog as of our current ingestion, and we have no independent corroboration.
What access does an attacker need to exploit this? Only a Subscriber-level WordPress account — the default tier granted to any self-registered user on a site with open registration enabled, per NVD’s description.
Does this create a federal patching deadline? No. Directive 26-04 obligations follow CISA KEV listing, and this CVE is not CISA-listed.
Is a fixed version available? Our source data does not carry a specific fixed version number beyond NVD’s statement that all versions “up to, and including, 3.35.0” are affected. Consult the plugin vendor directly for the current patched release.
Severity, vector, weakness classification, and the vulnerable function sourced from the National Vulnerability Database record for CVE-2026-14359, corroborated by Wordfence’s threat intelligence entry. Exploitation status and the September 9, 2026 catalog date reported by VulnCheck KEV, an authenticated feed with no public per-CVE page to cite. This CVE is not listed in CISA’s Known Exploited Vulnerabilities catalog as reflected in our current ingestion. EPSS score and percentile from FIRST’s Exploit Prediction Scoring System. Aggregated September 20, 2026. See more vulnerability intelligence.