CVE-2026-85128: Choose User Role at Registration for WooCommerce < 1.3.3 - Unauthenticated Privilege Escalation via Registration Role Request
The Choose User Role at Registration WordPress plugin before 1.3.3 does not validate the role requested at registration against the roles an administrator chose to offer, allowing unauthenticated users to request any role, including administrator, and to be granted it once the request is approved. Exploitation requires the Choose User Role at Registration WordPress plugin before 1.3.3's role selection feature and public account registration to both be enabled.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Choose User Role at Registration WordPress pluginto a version that resolves this vulnerability.Fixed in 1.3.3 - Configuration
Ensure exploitation conditions are not met by disabling either the plugin's role selection feature (for versions before 1.3.3) or public account registration until the plugin is upgraded to 1.3.3 or later.
Choose User Role at Registration WordPress plugin role selection feature and public account registration dependency = disable before patching
Event History
Frequently Asked Questions
Which sites are exposed to exploitation?
Sites using a version before 1.3.3 are exposed only when both the plugin's role-selection feature and public account registration are enabled.
What does an attacker need to do to gain elevated access?
An unauthenticated attacker can submit a registration request for any role, including administrator. The requested role is granted when that registration request is approved.
Does administrator approval prevent exploitation?
Approval is still required before the requested role is granted, but the plugin does not validate that the requested role is one the administrator intended to offer. Approvers should inspect requested roles carefully until the plugin is updated.