CVE-2026-3589: 
WordPress vulnerability analysis and mitigation

Overview

CVE-2026-3589 is a Cross-Site Request Forgery (CSRF) vulnerability in the WooCommerce WordPress plugin that allows unauthenticated attackers to create arbitrary administrator accounts by exploiting improper batch request handling. It affects WooCommerce versions 5.4.0 through 10.5.2 across a wide range of minor release branches. The vulnerability was publicly disclosed on March 3, 2026, with the CVE assigned on March 6, 2026, and was discovered by researcher oolongeya. It carries a CVSS v3.1 base score of 7.5 (High) (WPScan, Feedly).

Technical details

The root cause is improper handling of WooCommerce's batch request processing (CWE-352: Cross-Site Request Forgery), which fails to enforce proper authentication or CSRF token validation when routing batch sub-requests. An unauthenticated attacker can craft a malicious web page that, when visited by a logged-in WordPress administrator, causes the admin's browser to submit a batch request that proxies calls to non-store/non-WC REST API endpoints — such as the WordPress user creation endpoint — using the admin's authenticated session. This effectively bypasses the authentication requirement for privileged REST API operations by tunneling them through the WooCommerce Store API batch handler. Technical details and a write-up are available from the WooCommerce developer blog and the WPScan database (WPScan, WooCommerce Blog).

Impact

Successful exploitation allows an attacker to create arbitrary WordPress administrator accounts on the affected site, resulting in complete site compromise with high impact to confidentiality, integrity, and availability. With administrator access, an attacker can install malicious plugins, exfiltrate customer data (including payment information and personal details stored in WooCommerce), deface the site, or establish persistent backdoors for lateral movement within the hosting environment. Given WooCommerce's widespread deployment across e-commerce sites, the potential for sensitive financial and personal data exposure is significant (WPScan, Feedly).

Exploitability

No public exploit code or active in-the-wild exploitation has been confirmed at this time. The EPSS score is approximately 0.011% (0.000110), indicating a currently low probability of exploitation in the near term. The attack requires user interaction — specifically, a logged-in WordPress administrator must visit an attacker-controlled page — which raises the exploitation bar compared to fully unauthenticated attacks. The vulnerability is not currently listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, and no specific threat actor attribution has been reported (WPScan, Feedly).

Exploitation steps

  1. Reconnaissance: Identify WordPress sites running WooCommerce versions 5.4.0–10.5.2 using tools like WPScan, Shodan, or by inspecting publicly visible plugin version metadata in page source or readme.txt files.
  2. Craft malicious CSRF payload: Create an HTML page containing a JavaScript-driven or auto-submitting form that sends a POST request to the target site's WooCommerce Store API batch endpoint (e.g., /wp-json/wc/store/v1/batch) with a sub-request targeting the WordPress user creation REST endpoint (/wp-json/wp/v2/users) with administrator role parameters.
  3. Social engineer the administrator: Deliver the malicious page link to a logged-in WordPress site administrator via phishing email, comment, or other social engineering vector, causing their browser to automatically submit the forged batch request using their authenticated session cookies.
  4. Achieve privilege escalation: The batch handler processes the sub-request with the admin's credentials, creating a new administrator account with attacker-controlled credentials on the target WordPress/WooCommerce site.
  5. Establish persistence: Log in with the newly created admin account to install backdoor plugins, exfiltrate data, or further compromise the hosting environment (WPScan, WooCommerce Blog).

Indicators of compromise

  • Logs: WordPress access logs showing POST requests to /wp-json/wc/store/v1/batch containing sub-requests targeting /wp-json/wp/v2/users or other non-WC REST endpoints; unexpected new administrator user creation events in WordPress audit logs.
  • File System: Newly installed plugins or themes not authorized by legitimate administrators; presence of web shells or backdoor files in the WordPress uploads or plugins directories.
  • WordPress Admin: Unexpected administrator accounts appearing in the WordPress Users panel, particularly accounts with recently created timestamps and no associated order or customer history in WooCommerce.
  • Network: Outbound connections from the web server to unfamiliar external IPs following administrator account creation; unusual API traffic patterns to the WooCommerce Store API batch endpoint from external sources.

Mitigation and workarounds

WooCommerce has released patched versions across all affected branches; administrators should upgrade to the fixed version for their respective branch (e.g., 10.5.3, 10.4.4, 10.3.8, 10.2.4, 10.1.4, 10.0.6, 9.9.7, and corresponding patches for all 5.x–9.x branches). The full list of patched versions is available in the WPScan advisory. As a temporary workaround, administrators should avoid clicking links from untrusted sources while logged into WordPress, and consider restricting access to the WooCommerce REST API batch endpoint via WAF rules or server-level controls. Auditing existing administrator accounts for unauthorized entries is also recommended (WPScan, WooCommerce Blog).

Community reactions

The vulnerability was reported by researcher oolongeya and verified by WPScan, which published the advisory on March 3, 2026. The WooCommerce developer team published a dedicated blog post acknowledging the issue and detailing the patch. Coverage appeared across security aggregators including Vulners, CVEFeed, and InfinitSec, as well as social platforms such as Bluesky and Mastodon (infosec.exchange). The Roots.io WordPress security advisories feed also flagged the issue for Composer-based WordPress deployments (WPScan, WooCommerce Blog).

Additional resources


Source: This report was generated using AI

Related WordPress vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-86850MEDIUM6.5
  • sku-error-fixer-for-woocommerce
NoNoOct 06, 2026
CVE-2026-88931MEDIUM5.3
  • social-web-suite
NoNoOct 06, 2026
CVE-2026-87841MEDIUM5.3
  • unitechpay-paiements-mobile-money
NoNoOct 06, 2026
CVE-2026-92990MEDIUM5.3
  • sendpress
NoNoOct 06, 2026
CVE-2026-92989MEDIUM4.3
  • sendpress
NoNoOct 06, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management