PT-2026-64226 · Wpify · Wpify Woo – Withdrawal

·

CVE-2026-12736

·

Published

2026-07-24

·

Updated

2026-07-24

CVSS v3.1

8.0

High

VectorAV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H
The Wpify Woo plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 5.4.16. This is due to the SettingsApi::save option() REST route (POST /wp-json/wpify-woo/v1/option) passing the request-supplied 'option' and 'data' parameters directly to update option() without any option-name allowlist or value sanitization, while the permission callback only verifies the manage woocommerce capability. This makes it possible for authenticated attackers, with Shop Manager-level access and above, to elevate their privileges to Administrator by overwriting arbitrary WordPress options (for example setting default role to administrator and users can register to 1, or disabling security plugins via active plugins).

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-12736

Affected Products

Wpify Woo – Withdrawal