HarborGuardharborguardDatabase
Back to search
CRITICALCVE-2026-54807Published Modified CNA Patchstack

CVE-2026-54807: WordPress Registration Form for WooCommerce plugin <= 1.0.9 - Privilege Escalation vulnerability

Unauthenticated Privilege Escalation in Registration Form for WooCommerce <= 1.0.9 versions.

Metrics

CVSS v3.1
9.8
Severity
CRITICAL
Fixed in
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

An unauthenticated privilege escalation vulnerability affects the Registration Form for WooCommerce WordPress plugin by ThemeGrill at versions 1.0.9 and below. The flaw is reachable over the network without any credentials, meaning any internet-facing WordPress site running the plugin is exposed. Successful exploitation lets an attacker elevate their privileges within the WordPress installation, gaining read, write, and availability control over the affected site. No upstream fix has been published yet; HarborGuard tracks the advisory for patch availability.

HarborGuard Coverage

Detection

Detection for CVE-2026-54807 is available across every HarborGuard environment, with the CVE matched against customer images within minutes of publication using feeds from Patchstack and other upstream sources. Coverage extends to custom-built images that bundle WordPress or the Registration Form for WooCommerce plugin directly.

Available
Triage

HarborGuard is capable of scoring this finding at CVSS 9.8 Critical and weighting it against each customer environment's compliance policy to determine escalation priority. Routing to the appropriate team inbox within each customer organization is available automatically based on those policy settings.

Available
Patch

Because no fix version has been published upstream, HarborGuard re-checks the advisory each ingest cycle and will make a patched-image rebuild available the moment an upstream fix is released. In the meantime, customers can apply compensating controls through HarborGuard's policy engine while the advisory remains open.

Pending upstream

Exploit Conditions

  • Network reachabilityRequired

    The attacker must reach the WordPress service over the network; any internet-facing instance is directly exposed.

  • AuthenticationNot required

    No credentials of any kind are needed; the exploit is available to anonymous, unauthenticated requests.

  • Victim interactionNot required

    No action from a logged-in user or site visitor is required to trigger the vulnerability.

  • Attack complexityDetail

    Attack complexity is low, meaning the exploit is reliable and requires no special conditions, race timing, or environmental factors to succeed.

Blast Radius

  • An attacker gains elevated privileges within the WordPress installation, enabling full administrative access to site content, settings, and user accounts.
  • With high integrity impact, the attacker can create, modify, or delete posts, pages, plugins, and user records stored in the WordPress database.
  • With high confidentiality impact, the attacker reads stored user data, credentials, order records, and any WooCommerce customer information held in the database.
  • With high availability impact, the attacker can disable the site, remove critical content, or deactivate plugins and themes, taking the storefront offline.

How HarborGuard Handles This

Available on HarborGuard: because no upstream fix exists for CVE-2026-54807 at this time, HarborGuard continuously re-checks the advisory on every ingest cycle and will surface a patched-image rebuild the moment ThemeGrill publishes a fixed version. While the advisory remains open, compensating controls are available through HarborGuard's policy engine, including network-policy isolation to restrict public access to WordPress registration endpoints, egress filtering on affected container workloads, and advisory-watch alerts that fire immediately on upstream patch publication. For customers who opt into auto-remediation, a rebuilt image, regression-test run, and PR opened against affected workloads will be triggered automatically once a fix version is available, with median time from CVE publication to merged patch PR for critical-severity issues around 90 minutes for environments with auto-remediation enabled.

See how HarborGuard automates this
Affected packages
  • ThemeGrill / Registration Form for WooCommerce
    ≤ 1.0.9
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
References