What is CVE-2026-14279?
The CVE-2026-14279 vulnerability in the Wholesale Market plugin for WordPress allows privilege escalation via the `ced_wholesale_request_send` AJAX action in versions up to and including 2.2.2. The handler only checks a nonce exposed to any authenticated user, enabling unauthorized access to higher privileges. Immediate update to the latest patched version is recommended.
Azərbaycanca: WordPress-in Wholesale Market plaginində müəyyən edilən CVE-2026-14279 zəifliyi, 2.2.2 versiyasına qədər olan versiyalarda `ced_wholesale_request_send` AJAX funksiyası vasitəsilə imtiyaz yüksəltməyə (privilege escalation) imkan verir. Bu, autentifikasiya olunmuş istənilən istifadəçinin xüsusi nonce-i əldə edərək daha yüksək icazələr qazana bilməsi ilə nəticələnir. Plugin-i dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-862
FAQ2
Which versions of the Wholesale Market plugin for WordPress are affected by CVE-2026-14279?
This vulnerability exists in all versions of the plugin up to and including 2.2.2.
How can an authenticated user achieve privilege escalation using the CVE-2026-14279 vulnerability?
Any authenticated user can gain higher privileges by obtaining a specific nonce used in the `ced_wholesale_request_send` AJAX action.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.