CVE-2026-27541: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-27541 is an Incorrect Privilege Assignment vulnerability (CWE-266) in the Wholesale Suite WordPress plugin by Josh Kohlbach (Rymera Web Co), allowing authenticated attackers with Shop Manager-level access to escalate their privileges. It affects all versions of the plugin through 2.2.6, with version 2.2.7 released as the patched fix. The vulnerability was reported by researcher Teemu Saarentaus and published by Patchstack on February 20, 2026, with NVD publication on March 5, 2026. It carries a CVSS v3.1 base score of 7.2 (High) (Patchstack).

Technical details

The root cause is an Incorrect Privilege Assignment (CWE-266) within the Wholesale Suite plugin's handling of user roles or permissions, allowing a user with Shop Manager privileges to gain higher-level access than intended. The attack vector is network-based, requires no user interaction, and has low attack complexity, but does require the attacker to already hold a high-privilege account (Shop Manager) on the WordPress/WooCommerce installation. The vulnerability is classified under OWASP Top 10 category A7: Identification and Authentication Failures, and is tracked under Patchstack ID df6e7d4520f1 (Patchstack).

Impact

Successful exploitation allows an attacker with Shop Manager access to escalate their privileges to a higher level — potentially full administrative control of the WordPress site. This could result in complete compromise of the affected website, including unauthorized access to sensitive customer and order data (confidentiality impact), modification or deletion of site content and configurations (integrity impact), and potential disruption of site availability. Given the WooCommerce context, exposure of payment-related data and customer PII is a significant risk (Patchstack).

Exploitability

Patchstack has flagged this vulnerability as "Known to be exploited" (KEV) and notes it is expected to be used in mass-exploit campaigns targeting thousands of WordPress sites regardless of traffic size or popularity. The EPSS score is approximately 0.017% (0.000170), indicating a relatively low but non-negligible probability of exploitation in the near term. Exploitation requires an authenticated Shop Manager account, which limits opportunistic exploitation but does not eliminate risk in environments with multiple users or compromised credentials. No specific threat actor attribution or public PoC code has been identified at this time (Patchstack).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running the Wholesale Suite plugin (woocommerce-wholesale-prices) version 2.2.6 or earlier, using tools like WPScan or by inspecting plugin directories on target sites.
  2. Obtain Shop Manager credentials: Acquire a Shop Manager-level account through credential stuffing, phishing, purchasing access, or by registering if the site allows it.
  3. Authenticate: Log in to the WordPress/WooCommerce admin panel using the Shop Manager account.
  4. Trigger privilege escalation: Exploit the incorrect privilege assignment flaw within the Wholesale Suite plugin — likely by manipulating a role assignment, API endpoint, or plugin-specific functionality that improperly grants elevated permissions.
  5. Achieve elevated access: Gain administrator-level control of the WordPress site, enabling installation of backdoors, exfiltration of customer/payment data, or further lateral movement within the hosting environment (Patchstack).

Indicators of compromise

  • Logs: WordPress audit logs showing a Shop Manager account performing administrator-level actions (e.g., plugin installation, user role changes, settings modifications) unexpectedly.
  • Logs: Unusual role change events in the WordPress wp_usermeta table, particularly changes to wp_capabilities for Shop Manager accounts.
  • File System: Newly installed or modified plugins/themes not authorized by site administrators; presence of web shells or backdoor files in the WordPress directory.
  • Network: Unexpected outbound connections from the web server following admin-level actions by a Shop Manager account.
  • Process: Unusual PHP processes spawned from the web server user account after plugin interaction (Patchstack).

Mitigation and workarounds

The vendor has released version 2.2.7 of the Wholesale Suite plugin, which resolves this vulnerability — all users should update immediately. Patchstack users benefit from an automatically deployed virtual patch (mitigation rule) that blocks exploitation attempts until the plugin is updated, and auto-update for vulnerable plugins can be enabled via the Patchstack dashboard. As an interim measure, restrict Shop Manager account creation and review existing Shop Manager accounts for signs of unauthorized access (Patchstack).

Community reactions

Patchstack, which discovered and disclosed the vulnerability through its Active VDP program, has classified it as medium priority but flagged it as known to be exploited and likely to appear in mass-exploit campaigns. Wordfence also covered this vulnerability in its weekly WordPress vulnerability report for the period of February 16–22, 2026, indicating broader community awareness within the WordPress security ecosystem (Wordfence, Patchstack).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management