WordPress Plugin Vulnerabilities

WooCommerce < 10.5.3 - Arbitrary Admin User Creation via CSRF

Description

The plugin does not properly handle batch requests, which could allow unauthenticated users to make a logged in admin call non store/WC REST endpoints, and create arbitrary admin users via a CSRF attack for example.

Affects Plugins

Fixed in 10.5.3
Fixed in 10.4.4
Fixed in 10.3.8
Fixed in 10.2.4
Fixed in 10.1.4
Fixed in 10.0.6
Fixed in 9.9.7
Fixed in 9.8.7
Fixed in 9.7.3
Fixed in 9.6.4
Fixed in 9.5.4
Fixed in 9.4.5
Fixed in 9.3.6
Fixed in 9.2.5
Fixed in 9.1.7
Fixed in 9.0.4
Fixed in 8.9.5
Fixed in 8.8.7
Fixed in 8.7.3
Fixed in 8.6.4
Fixed in 8.5.5
Fixed in 8.4.3
Fixed in 8.3.4
Fixed in 8.2.5
Fixed in 8.1.4
Fixed in 8.0.5
Fixed in 7.9.2
Fixed in 7.8.4
Fixed in 7.7.3
Fixed in 7.6.2
Fixed in 7.5.2
Fixed in 7.4.2
Fixed in 7.3.1
Fixed in 7.2.4
Fixed in 7.1.2
Fixed in 7.0.2
Fixed in 6.9.5
Fixed in 6.8.3
Fixed in 6.7.1
Fixed in 6.6.2
Fixed in 6.5.2
Fixed in 6.4.2
Fixed in 6.3.2
Fixed in 6.2.3
Fixed in 6.1.3
Fixed in 6.0.2
Fixed in 5.9.2
Fixed in 5.8.2
Fixed in 5.7.3
Fixed in 5.6.3
Fixed in 5.5.5
Fixed in 5.4.4

References

Classification

Miscellaneous

Original Researcher
oolongeya
Verified
Yes

Timeline

Publicly Published
2026-03-03 (about 3 days ago)
Added
2026-03-03 (about 3 days ago)
Last Updated
2026-03-05 (about 1 day ago)

Other