The YITH WooCommerce Waitlist Premium plugin for WordPress is vulnerable to Privilege Escalation in versions up to, and including, 3.35.0. This is due to the add_user_in_waiting_list() function registered on the wp_ajax_yith_wcwtl_add_user action being missing both a capability check and a nonce verification, and using parse_str() + extract() to import attacker-controlled variables from $_POST['params'] that are then passed to wp_create_user() and $user->set_role(). This makes it possible for authenticated attackers, with Subscriber-level access and above, to elevate their privileges to that of an administrator by creating a new user account and assigning it the administrator role.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-09-09 09:17
Updated : 2026-09-09 16:17
NVD link : CVE-2026-14359
Mitre link : CVE-2026-14359
CVE.ORG link : CVE-2026-14359
JSON object : View
Products Affected
No product.
CWE
CWE-269
Improper Privilege Management
