WooCommerce CVE-2026-106608 (CVSS 7.2): a shop manager account can escalate its own privileges in WooCommerce 9.8.0 through 11.1.2; update the store plugin to 11.2.0
Patchstack published an advisory on 8 October 2026 for an incorrect privilege assignment flaw in WooCommerce, the Automattic e-commerce plugin for WordPress, and the CVE record (Patchstack as CVE numbering authority) followed on 10 October. Versions 9.8.0 through 11.1.2 are affected. Patchstack says the attacker needs a Shop manager account, the built-in WooCommerce role many stores hand to staff or contractors for orders and products, and that the flaw lets that account escalate privileges; it rates the issue CVSS 3.1 7.2 (network, low complexity, high privileges required, high impact on confidentiality, integrity and availability) and medium priority. The researcher, Ananda Dhakal of Patchstack, reported it on 25 August. Patchstack lists 11.2.0 as the patched version. No technical write-up or exploitation has been reported. The risk is mainly to stores where shop manager logins are shared, weakly protected or held by outside parties, since a takeover of one of those accounts could become a full site takeover. Primary: Patchstack advisory; CVE record.
- Product
- WooCommerce (Automattic) — WordPress e-commerce plugin
- Versions
- 9.8.0 through 11.1.2
- CVSS
- (CVSS 3.1, Patchstack)
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H - Exploited in Australia?
- unknown
- Patch to
- Update WooCommerce to 11.2.0 or later. Review who holds the Shop manager role, remove stale or shared accounts, require strong passwords and two-factor login for those users, and check for unexpected administrator accounts or role changes.
Primary: Patchstack — WooCommerce 9.8.0–11.1.2 Privilege Escalation (CVE-2026-106608, published 8 Oct 2026) · Vendor: WooCommerce changelog on WordPress.org · CVE: CVE-2026-106608 · CVE-2026-106608 — CVE record (Patchstack CNA, 10 Oct 2026)
