CVE-2026-27541

HIGH EXPLOITED LAB

Wholesale Suite <=2.2.6 - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2026-27541 has been observed exploited in the wild (reported by VulnCheck KEV). EIP tracks 1 public exploit from researchers including rootdirective-sec.

AI-analyzed exploit summary This repository contains a functional PoC for CVE-2026-27541, demonstrating an authenticated privilege escalation vulnerability in the WooCommerce Wholesale Prices plugin. The exploit leverages a broken access control issue where the `manage_woocommerce` capability is incorrectly used instead of `manage_options` for an admin settings endpoint.

Description

Incorrect Privilege Assignment vulnerability in Josh Kohlbach Wholesale Suite woocommerce-wholesale-prices allows Privilege Escalation.This issue affects Wholesale Suite: from n/a through <= 2.2.6.

Exploits (1)

nomisec WORKING POC
by rootdirective-sec · poc
https://github.com/rootdirective-sec/CVE-2026-27541-Analysis-Lab

This repository contains a functional PoC for CVE-2026-27541, demonstrating an authenticated privilege escalation vulnerability in the WooCommerce Wholesale Prices plugin. The exploit leverages a broken access control issue where the `manage_woocommerce` capability is incorrectly used instead of `manage_options` for an admin settings endpoint.

Classification
Working Poc 95%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: WooCommerce Wholesale Prices plugin versions 2.2.6 and below
Auth required
Prerequisites: Authenticated session as a user with `manage_woocommerce` capability (e.g., shop_manager role) · Valid nonce for the REST API endpoint
devstral-2 · analyzed Mar 19, 2026 Full analysis →

Scores

CVSS v3 7.2
EPSS 0.0005
EPSS Percentile 17.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Lab Environment

COMMUNITY
Community Lab
docker pull wordpress:cli-php8.2
docker pull wordpress:6.8.1-php8.2-apache

Details

VulnCheck KEV 2026-02-20
CWE
CWE-266
Status published
Products (1)
Josh Kohlbach/Wholesale Suite < 2.2.6
Published Mar 05, 2026
Tracked Since Mar 05, 2026