CVE-2026-27541

HIGH EXPLOITED LAB

Wholesale Suite <=2.2.6 - Privilege Escalation

Title source: llm

Description

Incorrect Privilege Assignment vulnerability in Josh Kohlbach Wholesale Suite woocommerce-wholesale-prices allows Privilege Escalation.This issue affects Wholesale Suite: from n/a through <= 2.2.6.

Exploits (1)

nomisec WORKING POC
by rootdirective-sec · poc
https://github.com/rootdirective-sec/CVE-2026-27541-Analysis-Lab

Scores

CVSS v3 7.1
EPSS 0.0005
EPSS Percentile 15.1%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:L

Lab Environment

COMMUNITY
Community Lab
docker pull wordpress:cli-php8.2
docker pull wordpress:6.8.1-php8.2-apache

Details

VulnCheck KEV 2026-02-20
CWE
CWE-266
Status published
Products (1)
Josh Kohlbach/Wholesale Suite < 2.2.6
Published Mar 05, 2026
Tracked Since Mar 05, 2026