Simple Registration for WooCommerce <= 1.5.8 - Cross-Site Request Forgery to Privilege Escalation via Role Request Approval
high
The Simple Registration for WooCommerce plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.5.8. This is due to missing nonce validation on the role requests admin page handler in the includes/display-role-admin.php file. This makes it possible for unauthenticated at...
- CVSS:
- 8.8
- Affected:
- up to 1.5.8
- Fixed in:
- 1.5.9
- Disclosed:
- Oct 24, 2025
CVE-2025-12095 on NVD →
Simple Registration for WooCommerce <= 1.5.6 - Unauthenticated Privilege Escalation
critical
The Simple Registration for WooCommerce plugin for WordPress is vulnerable to privilege escalation in all versions up to, and including, 1.5.6. This makes it possible for unauthenticated users to elevate their privileges to that of an administrator.
- CVSS:
- 9.8
- Affected:
- up to 1.5.6
- Fixed in:
- 1.5.7
- Disclosed:
- Apr 15, 2024
CVE-2024-32511 on NVD →
Protect your WordPress site
Run a free security scan to detect vulnerable plugins and themes, exposed files, and malware — no plugin install, no signup.
Scan your site free
← Back to the vulnerability database