CVE-2026-13152 is a privilege escalation vulnerability in the Custom Fields Account Registration For Woocommerce WordPress plugin before version 1.4. The plugin does not properly prevent custom registration fields from writing to the WordPress user capabilities metadata key on installations that use a non-default database table prefix. As a result, if a site administrator has configured a custom registration field whose name corresponds to the capabilities meta key for that prefixed installation, an unauthenticated user can supply crafted registration input during account creation and cause their newly created account to be assigned elevated privileges, including the administrator role.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
1 valid exploit after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a documentation-centric PoC/advisory for CVE-2026-13152 rather than a runnable exploit toolkit. It contains 4 files: LICENSE, README.md, SECURITY.md, and cve_2026_13152_writeup.md. There are no standalone scripts, binaries, or automation utilities; the only exploit material is embedded as illustrative HTML/PHP snippets inside Markdown documents. The vulnerability targets the WordPress plugin Custom Fields Account Registration For WooCommerce before version 1.4. The described flaw is an unauthenticated privilege escalation in the WooCommerce registration workflow: attacker-supplied custom registration fields are allegedly passed into update_user_meta() without filtering protected keys, allowing injection of privileged metadata such as wp_user_level and wp_capabilities. The PoC submits a POST request to the WooCommerce /my-account/ registration endpoint with hidden fields cfar_custom_fields[wp_user_level]=10 and cfar_custom_fields[wp_capabilities][administrator]=1, intending to create a new administrator account. Exploit capability: remote web-based account creation with privilege escalation to administrator. Follow-on impact described in the write-up includes access to /wp-admin/, plugin/theme installation, possible webshell upload, and full site compromise. Because the repository only provides a manual HTML form example and explanatory snippets, its maturity is best classified as POC. Notable fingerprintable targets and artifacts include the WooCommerce registration endpoint /my-account/, the WordPress admin path /wp-admin/, the wp_usermeta table, and sensitive meta keys wp_user_level, wp_capabilities, and session_tokens. Overall, the repository’s purpose is to publish a vulnerability advisory, root-cause explanation, remediation guidance, and a minimal browser-based proof of concept for validating the issue on authorized targets.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
No public activity tracked yet. Mallory keeps watching.
No public activity observed for this vulnerability.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.