WooCommerce Registration Fields CVE-2026-15369: Critical Security Update Checklist
August 29, 2026
WooCommerce Registration Fields CVE-2026-15369: Critical Security Update Checklist
Update Custom User Registration Fields for WooCommerce to version 2.2.4 or later now. NVD lists CVE-2026-15369 as a critical issue affecting versions through 2.2.3. The extension’s official WooCommerce Marketplace page lists 2.2.4 as current, and its official 2.2.4 changelog records a security fix and stronger validation for registration role assignment.
This is a patch-and-account-review task, not a reason to test a production checkout. Use normal change control and do not use public proof material against a live store.
Who should act
Review this notice if a WooCommerce store uses the Custom User Registration Fields for WooCommerce extension, especially when new customers can register during checkout or when the store offers optional role-based registration features.
Safe update plan
- Identify every store that has the extension installed and record its running version in the usual maintenance record.
- Schedule a staffed maintenance window and keep the site’s established administrator recovery path available. Preserve the normal change record before making the update.
- Install version 2.2.4 or later from the authorized WooCommerce Marketplace delivery path. Prefer the newest supported release after reviewing compatibility notes for the store’s WordPress, WooCommerce, and PHP versions.
- Confirm the checkout and ordinary account-registration journey still work as intended. Check that newly created customer accounts receive only the access the store has approved.
- Review recent administrator and customer-role changes using the store’s existing audit records. Escalate unexpected account changes through the site’s incident process rather than probing the checkout.
Reduce risk while maintenance is scheduled
If an immediate update cannot happen, temporarily turn off optional registration features that assign site roles, limit access to store administration, and monitor approved account-management records for unexpected changes. Remove temporary restrictions only after the patched store has been verified.
WooCommerce and WordPress maintenance
Keep the extension, WooCommerce, WordPress, themes, and other plugins current through their supported update paths. A security update should preserve checkout continuity as well as reduce risk, so use a maintenance window that includes an approved recovery path and a post-update storefront check. See Fix I.T. Phill WooCommerce Support and WordPress Support for help coordinating safe maintenance.
Sources and claim boundary
- NVD: CVE-2026-15369
- WooCommerce Marketplace: Custom User Registration Fields for WooCommerce
- Official extension changelog
Public sources checked for this guide confirm the affected version boundary and the vendor’s 2.2.4 security-fix statement. This guide does not claim active exploitation and does not include proof material, request details, or reproduction instructions.

