The WooCommerce WordPress plugin from versions 5.4.0 to 10.5.2 does not properly handle batch requests, which could allow unauthenticated users to make a logged in admin call non store/WC REST endpoints, and create arbitrary admin users via a CSRF attack for example.
History

Fri, 06 Mar 2026 18:15:00 +0000

Type Values Removed Values Added
Weaknesses CWE-352
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 06 Mar 2026 09:30:00 +0000

Type Values Removed Values Added
Description The WooCommerce WordPress plugin from versions 5.4.0 to 10.5.2 does not properly handle batch requests, which could allow unauthenticated users to make a logged in admin call non store/WC REST endpoints, and create arbitrary admin users via a CSRF attack for example.
Title WooCommerce < 10.5.3 - Arbitrary Admin User Creation via CSRF
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-03-06T17:44:58.613Z

Reserved: 2026-03-05T10:41:21.729Z

Link: CVE-2026-3589

cve-icon Vulnrichment

Updated: 2026-03-06T17:44:24.175Z

cve-icon NVD

Status : Received

Published: 2026-03-06T10:16:22.497

Modified: 2026-03-06T18:16:22.450

Link: CVE-2026-3589

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.