CVE-2026-3596Disclosure

LOWCVSS 9.8 · CRITICAL

Signal is active with 5 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

The Riaxe Product Customizer plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.1.2. The plugin registers an unauthenticated AJAX action ('wp_ajax_nopriv_install-imprint') that maps to the ink_pd_add_option() function. This function reads 'option' and 'opt_value' from $_POST, then calls delete_option() followed by add_option() using these attacker-controlled values without any nonce verification, capability checks, or option name allowlist. This makes it possible for unauthenticated attackers to update arbitrary WordPress options, which can be leveraged for privilege escalation by enabling user registration and setting the default user role to administrator.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-862

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Threat summary

  • Patch or workaround signal is available
  • 5 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 5 signals
  • Disclosure: 3 classified signals
  • General: 1 classified signal
  • 5 total mentions across 1 day

Deep dive

Activity timeline5 mentions / 1d
01345Mentions · 2026-04-16: 5Patch / Workaround · 2026-04-16: 2Technical Details · 2026-04-16: 504-16
Signal classification3 categories
Disclosure
360.0%
General
120.0%
Patch
120.0%
Referenced assets4 URLs
Full discourse5 posts
  • Orizon@OrizonCyber
    Patch

    🚨 CVE-2026-3596 — CVSS 9.8/10 ██████████ The Riaxe Product Customizer plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and... Severity: CRITICAL Patch now. #cybersecurity #CVE https://t.co/i8s7aV1Fyb

    Post summary

    The tweet alerts that CVE-2026-3596 is a critical privilege‑escalation flaw in the Riaxe Product Customizer plugin and urges users to apply the available patch.

    1000043
    23 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-3596 Privilege Escalation in Riaxe Product Customizer Plugin for WordPress Up to 2.1.2 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-3596

    Post summary

    The entry announces CVE-2026-3596 as a privilege‑escalation vulnerability affecting Riaxe Product Customizer Plugin up to version 2.1.2, providing only a reference link to a vulnerability database.

    0000036
    4.0K followersView on X
  • CVE@CVEnew
    General

    CVE-2026-3596 The Riaxe Product Customizer plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.1.2. The plugin registers an unauthentic… https://www.cve.org/CVERecord?id=CVE-2026-3596

    Post summary

    The statement reports a privilege escalation flaw in the Riaxe Product Customizer plugin, but provides no evidence of exploitation, PoC, or remediation.

    0000056
    57.2K followersView on X
  • Kaitan ID Security@KaitanSecurity
    Disclosure

    🚨 CRITICAL — CVE-2026-3596 The Riaxe Product Customizer plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and incl… CVSS 9.8 🔴 No patch yet Full analysis → https://sec.kaitan.id/cves/CVE-2026-3596 #WordPress #CyberSecurity #InfoSec

    Post summary

    CVE-2026-3596 is a critical privilege escalation vulnerability in the Riaxe Product Customizer WordPress plugin, rated CVSS 9.8, with no patch available yet.

    000003
    145 followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2026-3596: Riaxe Product Customizer <= 2.1.2... Zero-click WordPress admin takeover via unprotected AJAX endpoint that lets attackers flip any site option including use... https://zerodaysignal.com/vulnerability/CVE-2026-3596 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces CVE-2026-3596 as a zero‑click WordPress admin takeover flaw due to an unprotected AJAX endpoint in Riaxe Product Customizer v2.1.2 and related versions.

    0000073
    218 followersView on X

Explore more