Custom Fields Account Registration For WooCommerce <= 1.3 - Unauthenticated Privilege Escalation
critical
The Custom Fields Account Registration For Woocommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.3. This makes it possible for unauthenticated attackers to elevate their privileges to that of an administrator.
- CVSS:
- 9.8
- Affected:
- up to 1.3
- Fixed in:
- 1.4
- Disclosed:
- Jul 6, 2026
CVE-2026-13152 on NVD →
Custom Fields Account Registration For Woocommerce [custom-fields-account-registration-for-woocommerce] <= 1.2 (unfixed)
unknown
[en] Incorrect Privilege Assignment vulnerability in silverplugins217 Custom Fields Account Registration For Woocommerce custom-fields-account-registration-for-woocommerce allows Privilege Escalation.This issue affects Custom Fields Account Registration For Woocommerce: from n/a through <= 1.2.
- Affected:
- up to 1.2
- Fix:
- No patched version reported
- Disclosed:
- Dec 18, 2025
CVE-2025-49379 on NVD →
Custom Fields Account Registration For Woocommerce <= 1.2 - Authenticated (Author+) Privilege Escalation
high
The Custom Fields Account Registration For Woocommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.2. This makes it possible for authenticated attackers, with Author-level access and above, to elevate their privileges to that of an administrator.
- CVSS:
- 8.8
- Affected:
- up to 1.2
- Fixed in:
- 1.3
- Disclosed:
- Nov 10, 2025
CVE-2025-49379 on NVD →
Custom Fields Account Registration For Woocommerce <= 1.1 - Cross-Site Request Forgery
medium
The Custom Fields Account Registration For Woocommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.1. This is due to missing or incorrect nonce validation on a function. This makes it possible for unauthenticated attackers to perform an unauthorized action gr...
- CVSS:
- 4.3
- Affected:
- up to 1.1
- Fixed in:
- 1.2
- Disclosed:
- Mar 27, 2025
CVE-2025-30888 on NVD →
Custom Fields Account Registration For Woocommerce [custom-fields-account-registration-for-woocommerce] < 1.2
unknown
[en] Cross-Site Request Forgery (CSRF) vulnerability in silverplugins217 Custom Fields Account Registration For Woocommerce allows Cross Site Request Forgery. This issue affects Custom Fields Account Registration For Woocommerce: from n/a through 1.1.
- Affected:
- up to 1.2
- Fixed in:
- 1.2
- Disclosed:
- Mar 27, 2025
CVE-2025-30888 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database