What is CVE-2026-12144?
A critical Privilege Escalation vulnerability exists in the Wholesale for WooCommerce plugin for WordPress, affecting versions up to 2.0.5. The flaw in the `save_requests_meta()` function improperly handles the `user_role_set` POST parameter, allowing an authenticated user to escalate privileges to administrator. Immediate update to the latest patched version is required.
Azərbaycanca: WordPress üçün Wholesale for WooCommerce pluginində kritik imtiyaz yüksəltmə zəifliyi aşkarlanıb. 2.0.5 versiyasına qədər təsir edən bu boşluq `save_requests_meta()` funksiyasındakı `user_role_set` POST parametrinin düzgün yoxlanılmaması səbəbindən autentifikasiyalı istifadəçiyə administrator imtiyazları əldə etməyə imkan verir. Plugin dərhal ən son versiyaya yenilənməlidir.
Related CVEs
link basis: same weakness class CWE-269
FAQ2
Which versions of the Wholesale for WooCommerce plugin are affected by CVE-2026-12144?
The vulnerability affects all versions up to 2.0.5.
What does the CVE-2026-12144 vulnerability allow an authenticated user to do?
It allows an authenticated user to escalate privileges to administrator.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.