๐Ÿ” CVE Alert

CVE-2026-85128

HIGH 7.5

Choose User Role at Registration for WooCommerce < 1.3.3 - Unauthenticated Privilege Escalation via Registration Role Request

CVSS Score
7.5
EPSS Score
0.0%
EPSS Percentile
0th

The Choose User Role at Registration WordPress plugin before 1.3.3 does not validate the role requested at registration against the roles an administrator chose to offer, allowing unauthenticated users to request any role, including administrator, and to be granted it once the request is approved. Exploitation requires the Choose User Role at Registration WordPress plugin before 1.3.3's role selection feature and public account registration to both be enabled.

Vendor unknown
Product choose user role at registration
Published Sep 17, 2026
Last Updated Sep 17, 2026
Stay Ahead of the Next One

Get instant alerts for unknown choose user role at registration

Be the first to know when new high vulnerabilities affecting unknown choose user role at registration are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

Affected Versions

Unknown / Choose User Role at Registration
0 < 1.3.3

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
wpscan.com: https://wpscan.com/vulnerability/e48789a3-49b4-4fa4-8243-c242b79b9d9d/

Credits

Mike Gozdiskowski WPScan