HIGH
cedcommerce
CVE published 2026-08-15
CVE-2026-14279
The Wholesale Market plugin for WordPress has a vulnerability allowing privilege escalation up to version 2.2.2. Authenticated users with Subscriber-level access can elevate privileges to Administrator if the 'Assigning requested role directly' option is enabled. This vulnerability exists in the ced_wholesale_request_send AJAX action. The ced_wholesale_request_send_callback() handler only verifies a nonce [truncated]