CVE-2026-15369: Custom User Registration Fields for WooCommerce <= 2.2.3 - Unauthenticated Privilege Escalation via 'afreg_select_user_role' Parameter in Store API Checkout

Published Aug 29, 2026
·
Updated

The Custom User Registration Fields for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 2.2.3. This is due to the plugin accepting an attacker-controlled afregselectuserrole value from the unauthenticated WooCommerce Store API /wc/store/v1/checkout request in the afregcheckoutdatatoordermetadatablock() function, persisting it in order meta, and then passing it directly to WPUser::addrole() in the afregcustomorderprocessingfunction() function (hooked to woocommercethankyou) without validating against the plugin's admin-configured allowed role list. This makes it possible for unauthenticated attackers to elevate their privileges to Administrator by creating an account during checkout with a modified JSON body specifying administrator (or any other role slug) as the desired role. Note: The exploit requires the "User Role Selection" setting to be enabled.

Affected Software

1 affected component
WooCommerce Custom User Registration Fields for WooCommerce<=2.2.3

Event History

Aug 29, 2026
CVE Published
via MITRE·07:26 PM
Data Sourced
via MITRE·07:26 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which sites are exposed to unauthenticated administrator account creation?

Sites using affected versions up to 2.2.3 are exposed only when the plugin's "User Role Selection" setting is enabled. An attacker can submit a checkout request without existing credentials and specify the administrator role slug.

2

What must an attacker do to exploit this issue?

The attacker must create an account during checkout and send a modified JSON request body to the unauthenticated WooCommerce Store API /wc/store/v1/checkout endpoint. The request supplies afreg_select_user_role with administrator or another chosen role slug.

3

How can administrators determine whether their configuration is at risk?

Check whether Custom User Registration Fields for WooCommerce is version 2.2.3 or earlier and whether "User Role Selection" is enabled. The vulnerable path processes the afreg_select_user_role value supplied during Store API checkout.

4

What mitigation is available if an update cannot be applied immediately?

Disable the plugin's "User Role Selection" setting. The provided exploit condition requires that setting to be enabled.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203