CVE-2026-14359
Deferred Deferred - Pending Action

Privilege Escalation in YITH WooCommerce Waitlist Premium

Vulnerability report for CVE-2026-14359, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-09

Assigner: Wordfence

Description

The YITH WooCommerce Waitlist Premium plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 3.35.0. This is due to the add_user_in_waiting_list() function registered on the wp_ajax_yith_wcwtl_add_user action being missing both a capability check and a nonce verification, and using parse_str() + extract() to import attacker-controlled variables from $_POST['params'] that are then passed to wp_create_user() and $user->set_role(). This makes it possible for authenticated attackers, with Subscriber-level access and above, to elevate their privileges to that of an administrator by creating a new user account and assigning it the administrator role.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-09
Generated
2026-09-30
AI Q&A
2026-09-09
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
yith woocommerce_waitlist_premium to 3.35.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-269 The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a Privilege Escalation flaw in the YITH WooCommerce Waitlist Premium plugin for WordPress. It affects versions up to 3.35.0. The issue occurs because the add_user_in_waiting_list() function lacks proper security checks. Attackers with Subscriber-level access or higher can exploit this to create a new user account with administrator privileges by manipulating input variables.

Detection Guidance

Check for unauthorized user creation or role changes in WordPress admin logs. Inspect network traffic for POST requests to wp_ajax_yith_wcwtl_add_user with suspicious parameters. Use WordPress security plugins to monitor for privilege escalation attempts.

Impact Analysis

If you use the affected plugin, an attacker could gain full control of your WordPress site. This means they could install malicious software, steal data, or disrupt your website. The attack requires only a low-privilege account, making it easier for attackers to exploit.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR and HIPAA requirements. If attackers gain admin access, they may exfiltrate personal or health data, resulting in legal penalties, fines, and reputational damage for non-compliance.

Mitigation Strategies

Update the YITH WooCommerce Waitlist Premium plugin to the latest version. Remove Subscriber-level access for untrusted users. Implement strict capability checks and nonce verification in WordPress. Monitor for new admin accounts or privilege changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-14359. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart