Description
The WooCommerce Customers Manager plugin for WordPress is vulnerable to Privilege Escalation due to a missing capability check on the ajax_assign_new_roles() function in all versions up to, and including, 31.3. This makes it possible for authenticated attackers, with Subscriber-level access and above, to elevate their privileges to that of an administrator.
Problem types
CWE-269 Improper Privilege Management
Product status
* (semver)
Timeline
| 2025-01-31: | Disclosed |
Credits
Aiden
References
www.wordfence.com/...-17bc-47e7-b93d-dfcebcf8004d?source=cve
codecanyon.net/item/woocommerce-customers-manager/10965432