← WordPress Vulnerabilities
WordPress security by component

Custom Fields Account Registration For Woocommerce

Custom Fields Account Registration For Woocommerce is a WordPress component with 3 published CVE records in this archive. The latest tracked vulnerability was published Jul 27, 2026; the highest CVE/CNA score is 8.1.

Plugin slug: custom-fields-account-registration-for-woocommerce

CVE-2026-13152: WooCommerce registration fields can grant administrator capabilities

Custom Fields Account Registration For Woocommerce before 1.4 can write registration input into user-capability metadata when WordPress uses a non-default database table prefix. If an administrator has configured a correspondingly named registration field, an unauthenticated registrant can submit capability data that grants the new account administrator privileges. The CNA record does not disclose the field name, registration action, parameter or metadata-writing function.

PublishedJul 27, 2026
Known safe version1.4
Safe version
Jul 27, 2026 CVE-2026-13152
WooCommerce registration fields can grant administrator capabilities
Custom Fields Account Registration For Woocommerce before 1.4 can write registration input into user-capability metadata when WordPress uses a non-default database table prefix. If an administrator has configured a correspondingly named registration field, an unauthenticated registrant can submit capability data that grants the new account administrator privileges. The CNA record does not disclose the field name, registration action, parameter or metadata-writing function.
1.4
CVE8.1
NVDPending
Dec 18, 2025 CVE-2025-49379
Custom Fields Account Registration For Woocommerce: Privilege escalation or authentication bypass
Custom Fields Account Registration For Woocommerce is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.
See mitigation notes
CVE7.2
NVDPending
Mar 27, 2025 CVE-2025-30888
Custom Fields Account Registration For Woocommerce: Cross-site request forgery
Custom Fields Account Registration For Woocommerce is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
See mitigation notes
CVE4.3
NVDPending