Impact
The WPC Shop as a Customer for WooCommerce plugin contains a missing role validation in the wpcsa_login AJAX endpoint. An attacker who can authenticate as a subscriber or higher can supply any WordPress Administrator user ID and receive a full administrator session cookie. This direct session takeover gives the attacker complete administrator privileges, allowing modification of site content, user accounts, or core settings. The flaw is a classic example of broken access control, CWE‑269.
Affected Systems
The vulnerability affects all versions of the wpclever WPC Shop as a Customer for WooCommerce plugin up to and including 2.0.0 on any WordPress site where the plugin is active. Users should check the installed version and apply the fix if they are on an affected release.
Risk and Exploitability
With a CVSS score of 8.8, the flaw is considered high severity. No EPSS data is available, and the issue is not yet listed in CISA’s KEV catalog, but the attack vector is straightforward: a legitimate subscriber can send a crafted request to the AJAX endpoint, and the plugin will issue the admin session. The lack of mitigation in the code means exploitation can be carried out quickly with minimal technical skill.
OpenCVE Enrichment