CVE-2026-27541 PUBLISHED

WordPress Wholesale Suite plugin <= 2.2.6 - Privilege Escalation vulnerability

Assigner: Patchstack
Reserved: 20.02.2026 Published: 05.03.2026 Updated: 05.03.2026

Incorrect Privilege Assignment vulnerability in Josh Kohlbach Wholesale Suite woocommerce-wholesale-prices allows Privilege Escalation.This issue affects Wholesale Suite: from n/a through <= 2.2.6.

Product Status

Vendor Josh Kohlbach
Product Wholesale Suite
Versions Default: unaffected
  • affected from n/a to <= 2.2.6 (incl.)

Credits

  • Teemu Saarentaus | Patchstack Bug Bounty Program finder

References

Problem Types

  • Incorrect Privilege Assignment CWE

Impacts

  • Privilege Escalation