CVE-2026-85128: Choose User Role at Registration for WooCommerce < 1.3.3 - Unauthenticated Privilege Escalation via Registration Role Request

Published Sep 17, 2026
·
Updated

The Choose User Role at Registration WordPress plugin before 1.3.3 does not validate the role requested at registration against the roles an administrator chose to offer, allowing unauthenticated users to request any role, including administrator, and to be granted it once the request is approved. Exploitation requires the Choose User Role at Registration WordPress plugin before 1.3.3's role selection feature and public account registration to both be enabled.

Affected Software

1 affected component
WordPress Choose User Role at Registration (WordPress plugin)<1.3.3

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Choose User Role at Registration WordPress plugin to a version that resolves this vulnerability.

    Fixed in 1.3.3
  2. Configuration

    Ensure exploitation conditions are not met by disabling either the plugin's role selection feature (for versions before 1.3.3) or public account registration until the plugin is upgraded to 1.3.3 or later.

    Choose User Role at Registration WordPress plugin role selection feature and public account registration dependency = disable before patching

Event History

Sep 17, 2026
CVE Published
via MITRE·06:00 AM
Data Sourced
via MITRE·06:00 AM
DescriptionWeakness

Frequently Asked Questions

1

Which sites are exposed to exploitation?

Sites using a version before 1.3.3 are exposed only when both the plugin's role-selection feature and public account registration are enabled.

2

What does an attacker need to do to gain elevated access?

An unauthenticated attacker can submit a registration request for any role, including administrator. The requested role is granted when that registration request is approved.

3

Does administrator approval prevent exploitation?

Approval is still required before the requested role is granted, but the plugin does not validate that the requested role is one the administrator intended to offer. Approvers should inspect requested roles carefully until the plugin is updated.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203