CVE-2026-12144
saadiqbal Wholesale for WooCommerce
The Wholesale for WooCommerce plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.0.5. This is due to the `save_requests_meta()` function applying only `sanitize_text_field()` to the `user_role_set` POST parameter before passing it directly to `WP_User::add_role()`, with no allowlist validation against permitted wholesale roles and no capability check such as `current_user_can('promote_users')` or `current_user_can('manage_options')`. This makes it possible for authenticated attackers with author-level access and above to escalate their privile...
- CVSS
- 8.8
- EPSS
- 0.37% 29.6% percentile
- CISA KEV
- Not listed
- Published
- 2026.07.29