The WooCommerce WordPress plugin from versions 5.4.0 to 10.5.2 does not properly handle batch requests, which could allow unauthenticated users to make a logged in admin call non store/WC REST endpoints, and create arbitrary admin users via a CSRF attack for example.
History

Fri, 06 Mar 2026 09:30:00 +0000

Type Values Removed Values Added
Description The WooCommerce WordPress plugin from versions 5.4.0 to 10.5.2 does not properly handle batch requests, which could allow unauthenticated users to make a logged in admin call non store/WC REST endpoints, and create arbitrary admin users via a CSRF attack for example.
Title WooCommerce < 10.5.3 - Arbitrary Admin User Creation via CSRF
References

cve-icon MITRE

Status: PUBLISHED

Assigner: WPScan

Published:

Updated: 2026-03-06T09:11:10.949Z

Reserved: 2026-03-05T10:41:21.729Z

Link: CVE-2026-3589

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-03-06T10:16:22.497

Modified: 2026-03-06T10:16:22.497

Link: CVE-2026-3589

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.