TopVuln

High-risk vulnerability digests

CVE-2026-3596

  • CRITICAL

Details

CVSS v3
9.8
NVD published
2026-04-16 06:16:15
EPSS
<0.1% probability · 16.4th percentile — 2026-05-12
Affected versions
Riaxe Product Customizer plugin for WordPress, all versions up to and including 2.1.2
Summary
The Riaxe Product Customizer WordPress plugin contains an unauthenticated privilege escalation vulnerability. Its unprotected AJAX action allows attackers to modify arbitrary WordPress options without any authentication, capability checks, or nonce validation. Attackers can leverage this flaw to enable user registration and set the default user role to administrator, taking full control of the site.
Remediation
Update the Riaxe Product Customizer plugin to a patched version immediately. If no patch is available, remove the plugin from your WordPress installation to eliminate the vulnerability.
Exploit info
No public exploit found yet.

View on NVD

TopVuln sends digest emails with high-risk CVE picks across multiple authoritative sources—curated with EPSS and AI. Choose daily per-stream emails and optional weekly or monthly roundups.

Subscribe — free email digest or paid plan

Information is aggregated from multiple authoritative sources for convenience; verify with NVD and vendors before operational decisions.