Wholesale Suite <=2.2.6 - Privilege Escalation
Title source: llmExploitation Summary
CVE-2026-27541 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including rootdirective-sec.
AI-analyzed exploit summary This repository contains a functional PoC for CVE-2026-27541, demonstrating an authenticated privilege escalation vulnerability in the WooCommerce Wholesale Prices plugin. The exploit leverages a broken access control issue where the `manage_woocommerce` capability is incorrectly used instead of `manage_options` for an admin settings endpoint.
Description
Incorrect Privilege Assignment vulnerability in Josh Kohlbach Wholesale Suite woocommerce-wholesale-prices allows Privilege Escalation.This issue affects Wholesale Suite: from n/a through <= 2.2.6.
Exploits (1)
This repository contains a functional PoC for CVE-2026-27541, demonstrating an authenticated privilege escalation vulnerability in the WooCommerce Wholesale Prices plugin. The exploit leverages a broken access control issue where the `manage_woocommerce` capability is incorrectly used instead of `manage_options` for an admin settings endpoint.
References (1)
Scores
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H