Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-81431— Registration Form for WooCommerce 1.1.0 - 1.1.2 - Contributor+ Privilege Escalation via Unvalidated tgwcfb_id

Quick assessment

Affected
Unknown Registration Form for WooCommerce
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

WooCommerce 注册表单(Registration Form)插件在 1.1.3 版本之前未验证注册过程中引用的表单是否为合法的注册表单,而是从攻击者可控的任意文章(post)中读取允许的角色白名单。因此,能够创建文章的用户(Contributor 及以上权限)可以注册新账户并指定任意角色(包括管理员),从而导致站点被完全接管。此漏洞是 CVE-2026-54807 的不完全修复。

AI Predicted 8.1 Difficulty: Moderate

Possible ATT&CK Techniques 1 AI

T1078 · Valid Accounts
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-81431

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Registration Form for WooCommerce 1.1.0 - 1.1.2 - Contributor+ Privilege Escalation via Unvalidated tgwcfb_id
Source: CVE Program / CVE List V5
Vulnerability Description
The Registration Form for WooCommerce WordPress plugin before 1.1.3 does not validate that the form referenced during registration is a legitimate registration form, reading the permitted-role allow-list from an arbitrary attacker-controlled post instead. A user able to create a post (Contributor and above) can therefore register a new account with an arbitrary role, including Administrator, leading to full site takeover. This is an incomplete fix of CVE-2026-54807.
Source: CVE Program / CVE List V5
CVSS Information
N/A
Source: CVE Program / CVE List V5
Vulnerability Type
N/A
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
Unknown Registration Form for WooCommerce 1.1.0 ~ 1.1.3 -

II. Public POCs for CVE-2026-81431

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-81431

登录查看更多情报信息。

Proof of Concept for CVE-2026-81431 (1)

Same Patch Batch · Unknown · 2026-09-10 · 8 CVEs total

CVE-2026-82925 Site Reviews 7.2.2 - 8.2.2 - Unauthenticated PHP Object Injection via Form Signature
CVE-2026-77770 miniOrange 2FA (Free & Pro) - Unauthenticated Arbitrary Option Deletion via Out-of-Band Em
CVE-2026-77771 miniOrange 2FA (Free & Pro) - 2FA Bypass via Session-Scoped OTP Lockout
CVE-2026-78361 zipMoney(Zip Co) Payments Plugin for WooCommerce < 2.4.0 - Unauthenticated Arbitrary Optio
CVE-2026-19840 Notiqoo < 1.4.14 - Contributor+ Arbitrary Option Update via Multiple AJAX Actions
CVE-2026-19436 Ultimate Gift Cards For WooCommerce < 3.2.10 - Unauthenticated Gift Card Value Inflation v
CVE-2026-19439 Ultimate Gift Cards for WooCommerce 3.0.3 - 3.2.9 - Unauthenticated Gift Card Code and Cus

IV. Related Vulnerabilities

V. Comments for CVE-2026-81431

No comments yet


Leave a comment