PT-2026-33265 · WordPress · Riaxe Product Customizer
Kai Aizen
·
Published
2026-04-16
·
Updated
2026-04-16
·
CVE-2026-3596
CVSS v3.1
9.8
Critical
| AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Riaxe Product Customizer versions prior to 2.1.3
Description
The plugin contains a privilege escalation flaw due to an unauthenticated AJAX action ''wp ajax nopriv install-imprint'' that maps to the
ink pd add option() function. This function processes the option and opt value variables from $ POST and executes delete option() and add option() using these values without nonce verification, capability checks, or an option name allowlist. Unauthenticated attackers can update arbitrary WordPress options, which may be used to enable user registration and set the default user role to administrator, leading to full site takeover.Recommendations
Update to a version later than 2.1.2.
Fix
LPE
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Riaxe Product Customizer