---
id: CVE-2026-81431
title: >-
  The Registration Form for WooCommerce WordPress plugin before 1.1.3 does not
  validate that the form referenced during registration is a legitimate
  registration form, reading the permitted-role allow-list from an arbitrary
  attacker-contro…
summary: >-
  The Registration Form for WooCommerce WordPress plugin before 1.1.3 does not
  validate that the form referenced during registration is a legitimate
  registration form, reading the permitted-role allow-list from an arbitrary
  attacker-contro…
severity: high
cvss: 7.2
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-269
product: Registration Form for WooCommerce
affected:
  - registration_form_for_woocommerce >= 1.1.0 < 1.1.3
published: '2026-09-10'
updated: '2026-09-10'
sourceUpdated: '2026-09-10T15:13:07.090'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-81431'
references:
  - url: 'https://wpscan.com/vulnerability/e1255dd5-90d9-4ccf-9f84-3d1b41c5cba4/'
    label: contact@wpscan.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-10T13:10:03.394600Z'
ingestedAt: '2026-09-10T06:34:51.924Z'
epss: 0.00462
epssPercentile: 0.37404
---

## Overview

The Registration Form for WooCommerce WordPress plugin before 1.1.3 does not validate that the form referenced during registration is a legitimate registration form, reading the permitted-role allow-list from an arbitrary attacker-controlled post instead. A user able to create a post (Contributor and above) can therefore register a new account with an arbitrary role, including Administrator, leading to full site takeover. This is an incomplete fix of CVE-2026-54807.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
