
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27541 is an Incorrect Privilege Assignment vulnerability (CWE-266) in the Wholesale Suite WordPress plugin by Josh Kohlbach (Rymera Web Co), allowing authenticated attackers with Shop Manager-level access to escalate their privileges. It affects all versions of the plugin through 2.2.6, with version 2.2.7 released as the patched fix. The vulnerability was reported by researcher Teemu Saarentaus and published by Patchstack on February 20, 2026, with NVD publication on March 5, 2026. It carries a CVSS v3.1 base score of 7.2 (High) (Patchstack).
The root cause is an Incorrect Privilege Assignment (CWE-266) within the Wholesale Suite plugin's handling of user roles or permissions, allowing a user with Shop Manager privileges to gain higher-level access than intended. The attack vector is network-based, requires no user interaction, and has low attack complexity, but does require the attacker to already hold a high-privilege account (Shop Manager) on the WordPress/WooCommerce installation. The vulnerability is classified under OWASP Top 10 category A7: Identification and Authentication Failures, and is tracked under Patchstack ID df6e7d4520f1 (Patchstack).
Successful exploitation allows an attacker with Shop Manager access to escalate their privileges to a higher level — potentially full administrative control of the WordPress site. This could result in complete compromise of the affected website, including unauthorized access to sensitive customer and order data (confidentiality impact), modification or deletion of site content and configurations (integrity impact), and potential disruption of site availability. Given the WooCommerce context, exposure of payment-related data and customer PII is a significant risk (Patchstack).
Patchstack has flagged this vulnerability as "Known to be exploited" (KEV) and notes it is expected to be used in mass-exploit campaigns targeting thousands of WordPress sites regardless of traffic size or popularity. The EPSS score is approximately 0.017% (0.000170), indicating a relatively low but non-negligible probability of exploitation in the near term. Exploitation requires an authenticated Shop Manager account, which limits opportunistic exploitation but does not eliminate risk in environments with multiple users or compromised credentials. No specific threat actor attribution or public PoC code has been identified at this time (Patchstack).
wp_usermeta table, particularly changes to wp_capabilities for Shop Manager accounts.The vendor has released version 2.2.7 of the Wholesale Suite plugin, which resolves this vulnerability — all users should update immediately. Patchstack users benefit from an automatically deployed virtual patch (mitigation rule) that blocks exploitation attempts until the plugin is updated, and auto-update for vulnerable plugins can be enabled via the Patchstack dashboard. As an interim measure, restrict Shop Manager account creation and review existing Shop Manager accounts for signs of unauthorized access (Patchstack).
Patchstack, which discovered and disclosed the vulnerability through its Active VDP program, has classified it as medium priority but flagged it as known to be exploited and likely to appear in mass-exploit campaigns. Wordfence also covered this vulnerability in its weekly WordPress vulnerability report for the period of February 16–22, 2026, indicating broader community awareness within the WordPress security ecosystem (Wordfence, Patchstack).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."