CVE-2026-13152

HIGH

Custom Fields Account Registration For WooCommerce < 1.4 - Unauthenticated Privilege Escalation

Title source: cna
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2026-13152. PoCs published by incogbyte.

AI-analyzed exploit summary This exploit demonstrates an unauthenticated privilege escalation vulnerability in the 'Custom Fields Account Registration For WooCommerce' plugin (<=1.3) by abusing unblocked user-meta writes during WooCommerce registration. Attackers can inject arbitrary capabilities (e.g., administrator role) by submitting crafted values to a pre-existing custom registration field whose slug matches the site's actual '<table_prefix>capabilities' meta key.

Description

The Custom Fields Account Registration For Woocommerce WordPress plugin before 1.4 does not prevent its custom registration fields from writing to the user capabilities meta key on sites that use a non-default database table prefix, so an unauthenticated user who registers an account can be granted the administrator role when a correspondingly named field has been configured.

Exploits (1)

github WORKING POC 5 stars
by incogbyte · pythonpoc
https://github.com/incogbyte/wp-cve-exploits/tree/main/CVE-2026-13152

This exploit demonstrates an unauthenticated privilege escalation vulnerability in the 'Custom Fields Account Registration For WooCommerce' plugin (<=1.3) by abusing unblocked user-meta writes during WooCommerce registration. Attackers can inject arbitrary capabilities (e.g., administrator role) by submitting crafted values to a pre-existing custom registration field whose slug matches the site's actual '<table_prefix>capabilities' meta key.

Classification
Working Poc 99%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Custom Fields Account Registration For WooCommerce <= 1.3
No auth needed
Prerequisites: WooCommerce registration enabled on the target's My Account page · A pre-existing custom registration field with a slug matching the site's actual '<table_prefix>capabilities' meta key (e.g., 'wp_custom_capabilities') · Field type must submit as an array (e.g., multicheckbox/multiselect)
mistral-large-3 · analyzed Jul 30, 2026 Full analysis →

References (1)

Core 1
Core References
Exploit exploit vdb-entry technical-description
https://wpscan.com/vulnerability/36aaba38-3143-4e80-8386-748632ff6704/

Scores

CVSS v3 8.1
EPSS 0.0023
EPSS Percentile 13.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-269
Status published
Products (1)
None/Custom Fields Account Registration For Woocommerce < 1.4
Published Jul 27, 2026
Tracked Since Jul 27, 2026