Riaxe Product Customizer Privilege Escalation Vulnerability

Vulnerability

A privilege escalation vulnerability exists in the Riaxe Product Customizer plugin for WordPress, affecting all versions through 2.1.2. The vulnerability arises from an unauthenticated AJAX action that allows attackers to update arbitrary WordPress options without proper authorization. The 'wp_ajax_nopriv_install-imprint' action, linked to the 'ink_pd_add_option()' function, lacks nonce verification, capability checks, and an option name allowlist. This oversight enables unauthenticated attackers to manipulate WordPress options, potentially escalating privileges by enabling user registration and assigning the default user role as administrator.

Impact

Exploitation of this vulnerability allows unauthenticated attackers to update WordPress options arbitrarily, with the potential to escalate privileges by enabling user registration and designating new users as administrators.

Added: Apr 16, 2026, 7:59 AM
Updated: Apr 16, 2026, 7:59 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
2.5
exploitability
8.1
remediation
0.0
relevance
6.0
threat
3.2
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.