CVE-2026-54807: WordPress Registration Form for WooCommerce plugin <= 1.0.9 - Privilege Escalation vulnerability
Unauthenticated Privilege Escalation in Registration Form for WooCommerce <= 1.0.9 versions.
Metrics
- CVSS v3.1
- 9.8
- Severity
- CRITICAL
- Fixed in
- —
- Affected Products
- 1
HarborGuard Analysis
Synopsis
An unauthenticated privilege escalation vulnerability affects the Registration Form for WooCommerce WordPress plugin by ThemeGrill at versions 1.0.9 and below. The flaw is reachable over the network without any credentials, meaning any internet-facing WordPress site running the plugin is exposed. Successful exploitation lets an attacker elevate their privileges within the WordPress installation, gaining read, write, and availability control over the affected site. No upstream fix has been published yet; HarborGuard tracks the advisory for patch availability.
HarborGuard Coverage
Detection for CVE-2026-54807 is available across every HarborGuard environment, with the CVE matched against customer images within minutes of publication using feeds from Patchstack and other upstream sources. Coverage extends to custom-built images that bundle WordPress or the Registration Form for WooCommerce plugin directly.
AvailableHarborGuard is capable of scoring this finding at CVSS 9.8 Critical and weighting it against each customer environment's compliance policy to determine escalation priority. Routing to the appropriate team inbox within each customer organization is available automatically based on those policy settings.
AvailableBecause no fix version has been published upstream, HarborGuard re-checks the advisory each ingest cycle and will make a patched-image rebuild available the moment an upstream fix is released. In the meantime, customers can apply compensating controls through HarborGuard's policy engine while the advisory remains open.
Pending upstreamExploit Conditions
- Network reachabilityRequired
The attacker must reach the WordPress service over the network; any internet-facing instance is directly exposed.
- AuthenticationNot required
No credentials of any kind are needed; the exploit is available to anonymous, unauthenticated requests.
- Victim interactionNot required
No action from a logged-in user or site visitor is required to trigger the vulnerability.
- Attack complexityDetail
Attack complexity is low, meaning the exploit is reliable and requires no special conditions, race timing, or environmental factors to succeed.
Blast Radius
- An attacker gains elevated privileges within the WordPress installation, enabling full administrative access to site content, settings, and user accounts.
- With high integrity impact, the attacker can create, modify, or delete posts, pages, plugins, and user records stored in the WordPress database.
- With high confidentiality impact, the attacker reads stored user data, credentials, order records, and any WooCommerce customer information held in the database.
- With high availability impact, the attacker can disable the site, remove critical content, or deactivate plugins and themes, taking the storefront offline.
How HarborGuard Handles This
Available on HarborGuard: because no upstream fix exists for CVE-2026-54807 at this time, HarborGuard continuously re-checks the advisory on every ingest cycle and will surface a patched-image rebuild the moment ThemeGrill publishes a fixed version. While the advisory remains open, compensating controls are available through HarborGuard's policy engine, including network-policy isolation to restrict public access to WordPress registration endpoints, egress filtering on affected container workloads, and advisory-watch alerts that fire immediately on upstream patch publication. For customers who opt into auto-remediation, a rebuilt image, regression-test run, and PR opened against affected workloads will be triggered automatically once a fix version is available, with median time from CVE publication to merged patch PR for critical-severity issues around 90 minutes for environments with auto-remediation enabled.
- ThemeGrill / Registration Form for WooCommerce≤ 1.0.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H