
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-3589 is a Cross-Site Request Forgery (CSRF) vulnerability in the WooCommerce WordPress plugin that allows unauthenticated attackers to create arbitrary administrator accounts by exploiting improper batch request handling. It affects WooCommerce versions 5.4.0 through 10.5.2 across a wide range of minor release branches. The vulnerability was publicly disclosed on March 3, 2026, with the CVE assigned on March 6, 2026, and was discovered by researcher oolongeya. It carries a CVSS v3.1 base score of 7.5 (High) (WPScan, Feedly).
The root cause is improper handling of WooCommerce's batch request processing (CWE-352: Cross-Site Request Forgery), which fails to enforce proper authentication or CSRF token validation when routing batch sub-requests. An unauthenticated attacker can craft a malicious web page that, when visited by a logged-in WordPress administrator, causes the admin's browser to submit a batch request that proxies calls to non-store/non-WC REST API endpoints — such as the WordPress user creation endpoint — using the admin's authenticated session. This effectively bypasses the authentication requirement for privileged REST API operations by tunneling them through the WooCommerce Store API batch handler. Technical details and a write-up are available from the WooCommerce developer blog and the WPScan database (WPScan, WooCommerce Blog).
Successful exploitation allows an attacker to create arbitrary WordPress administrator accounts on the affected site, resulting in complete site compromise with high impact to confidentiality, integrity, and availability. With administrator access, an attacker can install malicious plugins, exfiltrate customer data (including payment information and personal details stored in WooCommerce), deface the site, or establish persistent backdoors for lateral movement within the hosting environment. Given WooCommerce's widespread deployment across e-commerce sites, the potential for sensitive financial and personal data exposure is significant (WPScan, Feedly).
No public exploit code or active in-the-wild exploitation has been confirmed at this time. The EPSS score is approximately 0.011% (0.000110), indicating a currently low probability of exploitation in the near term. The attack requires user interaction — specifically, a logged-in WordPress administrator must visit an attacker-controlled page — which raises the exploitation bar compared to fully unauthenticated attacks. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no specific threat actor attribution has been reported (WPScan, Feedly).
readme.txt files./wp-json/wc/store/v1/batch) with a sub-request targeting the WordPress user creation REST endpoint (/wp-json/wp/v2/users) with administrator role parameters./wp-json/wc/store/v1/batch containing sub-requests targeting /wp-json/wp/v2/users or other non-WC REST endpoints; unexpected new administrator user creation events in WordPress audit logs.WooCommerce has released patched versions across all affected branches; administrators should upgrade to the fixed version for their respective branch (e.g., 10.5.3, 10.4.4, 10.3.8, 10.2.4, 10.1.4, 10.0.6, 9.9.7, and corresponding patches for all 5.x–9.x branches). The full list of patched versions is available in the WPScan advisory. As a temporary workaround, administrators should avoid clicking links from untrusted sources while logged into WordPress, and consider restricting access to the WooCommerce REST API batch endpoint via WAF rules or server-level controls. Auditing existing administrator accounts for unauthorized entries is also recommended (WPScan, WooCommerce Blog).
The vulnerability was reported by researcher oolongeya and verified by WPScan, which published the advisory on March 3, 2026. The WooCommerce developer team published a dedicated blog post acknowledging the issue and detailing the patch. Coverage appeared across security aggregators including Vulners, CVEFeed, and InfinitSec, as well as social platforms such as Bluesky and Mastodon (infosec.exchange). The Roots.io WordPress security advisories feed also flagged the issue for Composer-based WordPress deployments (WPScan, WooCommerce Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."