Privilege Escalation in WPC Shop as a Customer for WooCommerce
An improper role validation vulnerability in the WPC Shop as a Customer for WooCommerce plugin allows authenticated attackers to perform account takeover and gain administrative access via the wpcsa_login endpoint.
CVE search metadata
CVE search record: CVE-2026-95687. Severity: high. CVSS: 8.8. KEV: no. Product: WPC Shop as a Customer for WooCommerce (<= 2.0.0). Brief: Privilege Escalation in WPC Shop as a Customer for WooCommerce. Brief link: https://feed.craftedsignal.io/briefs/2026-10-cve-2026-95687/
The WPC Shop as a Customer for WooCommerce plugin for WordPress is vulnerable to privilege escalation in all versions up to and including 2.0.0. The vulnerability stems from a lack of proper role validation within the wpcsa_login endpoint. An attacker with a standard authenticated account can interact with this endpoint and supply a target administrator's user ID. The plugin subsequently fails to verify the requester's authority, granting the attacker a valid session cookie associated with the target administrator account. This bypasses the need for the administrator's password, effectively resulting in a full administrative account takeover. This flaw is critical for WordPress environments using WooCommerce, as it allows unauthorized users to modify site settings, install malicious plugins, or exfiltrate sensitive customer data.
Attack Chain
- Attacker authenticates with a low-privileged account on a target WordPress site.
- Attacker enumerates the target administrator user ID (e.g., via author archives or author rest API endpoints).
- Attacker crafts an HTTP request targeting the vulnerable /wpcsa_login endpoint.
- Attacker includes the target administrator's user ID as a parameter in the request.
- The plugin server-side logic processes the request without validating if the current session has the capability to initiate a login as another user.
- The server issues a valid session cookie for the administrator account to the attacker.
- Attacker updates their browser session with the stolen administrator cookie to gain full site control.
Impact
Successful exploitation allows an authenticated attacker to gain full WordPress administrative control. This leads to complete site compromise, including the ability to execute arbitrary code via plugin installation, manipulate WooCommerce order data, and potentially access sensitive user information stored within the WordPress database.
Recommendation
- Update the WPC Shop as a Customer for WooCommerce plugin to the version containing the patch for CVE-2026-95687 immediately.
- If a patch is unavailable, deactivate or remove the WPC Shop as a Customer for WooCommerce plugin from production WordPress environments.
- Monitor access logs for repeated or unusual POST requests to the 'wpcsa_login' URI stem, particularly those associated with low-privileged user accounts.
- Audit WordPress user accounts to identify unauthorized administrative changes or newly created administrator accounts.
Immediate actions
Audit web access logs for calls to /wpcsa_login
Mitigations
Upgrade WPC Shop as a Customer for WooCommerce to a version > 2.0.0
CVE-2026-95687
Detection coverage 1
Detect CVE-2026-95687 Exploitation - Privilege Escalation via wpcsa_login
highDetects potential exploitation attempts of CVE-2026-95687 where an authenticated user interacts with the wpcsa_login endpoint to assume another user's session.
Detection queries are available on the platform. Get full rules →