CVE-2026-106608: WordPress WooCommerce plugin 9.8.0-11.1.2 - Shop Manager+ Privilege Escalation vulnerability
Incorrect Privilege Assignment vulnerability in Automattic WooCommerce woocommerce allows Privilege Escalation.This issue affects WooCommerce: from 9.8.0 through 11.1.2.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
WordPress WooCommerce pluginto a version that resolves this vulnerability.Fixed in 11.2.0
Event History
Frequently Asked Questions
Which WooCommerce deployments are affected?
Deployments running Automattic WooCommerce versions 9.8.0 through 11.1.2 are affected.
Does exploitation require an existing account?
Yes. The CVSS vector specifies high privileges required (PR:H), so an attacker must already have a highly privileged account or equivalent access. The attack can be conducted over the network and does not require user interaction.
What could successful exploitation allow?
The issue is a privilege-escalation vulnerability. Its CVSS impacts indicate high potential impact to confidentiality, integrity, and availability.