Description
The WPC Shop as a Customer for WooCommerce plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.0.0 This is due to the plugin not properly validating the target user's role prior to issuing a new authentication session, allowing an authenticated attacker to log in as any WordPress Administrator by directly supplying an Administrator's user ID to the wpcsa_login endpoint and receiving a full Administrator session cookie without supplying the Administrator's password. This makes it possible for authenticated attackers to perform a direct session takeover, gaining full Administrator-level access to the site.
Published: 2026-10-01
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: Privilege Escalation to Administrator
Action: Immediate Patch
AI Analysis

Impact

The WPC Shop as a Customer for WooCommerce plugin contains a missing role validation in the wpcsa_login AJAX endpoint. An attacker who can authenticate as a subscriber or higher can supply any WordPress Administrator user ID and receive a full administrator session cookie. This direct session takeover gives the attacker complete administrator privileges, allowing modification of site content, user accounts, or core settings. The flaw is a classic example of broken access control, CWE‑269.

Affected Systems

The vulnerability affects all versions of the wpclever WPC Shop as a Customer for WooCommerce plugin up to and including 2.0.0 on any WordPress site where the plugin is active. Users should check the installed version and apply the fix if they are on an affected release.

Risk and Exploitability

With a CVSS score of 8.8, the flaw is considered high severity. No EPSS data is available, and the issue is not yet listed in CISA’s KEV catalog, but the attack vector is straightforward: a legitimate subscriber can send a crafted request to the AJAX endpoint, and the plugin will issue the admin session. The lack of mitigation in the code means exploitation can be carried out quickly with minimal technical skill.

Generated by OpenCVE AI on October 1, 2026 at 11:05 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the WPC Shop as a Customer for WooCommerce plugin to version 2.0.1 or later.
  • If an upgrade cannot be performed immediately, block or restrict access to the wpcsa_login AJAX endpoint so it can only be called by users with Administrator capability.
  • When feasible, disable the plugin on sites where it is not essential until the fix is applied.

Generated by OpenCVE AI on October 1, 2026 at 11:05 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 01 Oct 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress-extensions
Wordpress-extensions wpc Shop As A Customer For Woocommerce
Wpclever
Wpclever wpc Shop As A Customer For Woocommerce
Vendors & Products Wordpress-extensions
Wordpress-extensions wpc Shop As A Customer For Woocommerce
Wpclever
Wpclever wpc Shop As A Customer For Woocommerce

Thu, 01 Oct 2026 09:00:00 +0000

Type Values Removed Values Added
Description The WPC Shop as a Customer for WooCommerce plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.0.0 This is due to the plugin not properly validating the target user's role prior to issuing a new authentication session, allowing an authenticated attacker to log in as any WordPress Administrator by directly supplying an Administrator's user ID to the wpcsa_login endpoint and receiving a full Administrator session cookie without supplying the Administrator's password. This makes it possible for authenticated attackers to perform a direct session takeover, gaining full Administrator-level access to the site.
Title WPC Shop as a Customer for WooCommerce <= 2.0.0 - Authenticated (Subscriber+) Privilege Escalation via Missing Role Check on Target User to wpcsa_login AJAX Endpoint
Weaknesses CWE-269
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Wordpress-extensions Wpc Shop As A Customer For Woocommerce
Wpclever Wpc Shop As A Customer For Woocommerce
cve-icon MITRE

Status: PUBLISHED

Assigner: Wordfence

Published:

Updated: 2026-10-01T08:28:43.728Z

Reserved: 2026-09-22T14:14:09.896Z

Link: CVE-2026-95687

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-01T09:17:10.273

Modified: 2026-10-01T12:40:28.083

Link: CVE-2026-95687

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-01T15:36:00Z

Weaknesses
  • CWE-269

    Improper Privilege Management