PatchSiren

cedcommerce CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH cedcommerce CVE published 2026-08-15

CVE-2026-14279

The Wholesale Market plugin for WordPress has a vulnerability allowing privilege escalation up to version 2.2.2. Authenticated users with Subscriber-level access can elevate privileges to Administrator if the 'Assigning requested role directly' option is enabled. This vulnerability exists in the ced_wholesale_request_send AJAX action. The ced_wholesale_request_send_callback() handler only verifies a nonce [truncated]