WordPress security by component
Custom Fields Account Registration For Woocommerce
Plugin description
Custom Fields Account Registration For Woocommerce is a WordPress component with 3 published CVE records in this archive. The latest tracked vulnerability was published Jul 27, 2026; the highest CVE/CNA score is 8.1.
Plugin slug:
custom-fields-account-registration-for-woocommerceLatest vulnerability
CVE-2026-13152: WooCommerce registration fields can grant administrator capabilities
Custom Fields Account Registration For Woocommerce before 1.4 can write registration input into user-capability metadata when WordPress uses a non-default database table prefix. If an administrator has configured a correspondingly named registration field, an unauthenticated registrant can submit capability data that grants the new account administrator privileges. The CNA record does not disclose the field name, registration action, parameter or metadata-writing function.
| Safe version |
|
||
|---|---|---|---|
| Jul 27, 2026 |
CVE-2026-13152
WooCommerce registration fields can grant administrator capabilities
Custom Fields Account Registration For Woocommerce before 1.4 can write registration input into user-capability metadata when WordPress uses a non-default database table prefix. If an administrator has configured a correspondingly named registration field, an unauthenticated registrant can submit capability data that grants the new account administrator privileges. The CNA record does not disclose the field name, registration action, parameter or metadata-writing function.
|
1.4 |
CVE8.1
NVDPending
|
| Dec 18, 2025 |
CVE-2025-49379
Custom Fields Account Registration For Woocommerce: Privilege escalation or authentication bypass
Custom Fields Account Registration For Woocommerce is affected by privilege escalation or authentication bypass. Exposure depends on how the affected operation is made reachable by the site. A successful request can grant permissions or access that the caller should not possess.
|
See mitigation notes |
CVE7.2
NVDPending
|
| Mar 27, 2025 |
CVE-2025-30888
Custom Fields Account Registration For Woocommerce: Cross-site request forgery
Custom Fields Account Registration For Woocommerce is affected by cross-site request forgery. Exposure depends on how the affected operation is made reachable by the site. Exploitation relies on a signed-in privileged user submitting an attacker-controlled request.
|
See mitigation notes |
CVE4.3
NVDPending
|