Skip to content
Threat Feed
high advisory

Privilege Escalation in FooSales POS for WooCommerce

An authentication flaw in FooSales POS for WooCommerce (<= 1.43.0) allows authenticated users with cashier permissions to perform account takeover by modifying arbitrary user email addresses.

CVE search metadata

CVE search record: CVE-2026-77183. Severity: high. CVSS: 8.8. KEV: no. Product: FooSales – Point of Sale (POS) for WooCommerce (<= 1.43.0). Brief: Privilege Escalation in FooSales POS for WooCommerce. Brief link: https://feed.craftedsignal.io/briefs/2026-10-foosales-privilege-escalation/

The FooSales - Point of Sale (POS) for WooCommerce plugin for WordPress is vulnerable to privilege escalation via an insecure account detail update mechanism present in all versions up to, and including, 1.43.0. The vulnerability stems from the plugin's failure to properly validate a user's identity before allowing updates to sensitive account fields such as the email address. An authenticated attacker possessing at least FooSales Cashier-level access can exploit this flaw to overwrite the email address of any user in the WordPress system, including administrative accounts. By redirecting the email address, the attacker can subsequently trigger a standard WordPress password reset request, receive the reset token, and gain full control over the compromised account. This vulnerability poses a significant risk to e-commerce environments where site integrity and administrative access are critical.

Attack Chain

  1. Attacker authenticates to the WordPress site using a low-privilege account with FooSales Cashier permissions.
  2. Attacker interacts with the FooSales plugin's account update functionality to modify profile information.
  3. Attacker sends a crafted HTTP POST request to the server, targeting the vulnerable user-update endpoint with an arbitrary email address.
  4. The plugin processes the request without sufficient identity validation, successfully updating the target administrator's email to an address controlled by the attacker.
  5. Attacker navigates to the WordPress password reset page (wp-login.php?action=lostpassword) and requests a reset for the targeted administrator account.
  6. The WordPress system sends the password reset token to the attacker-controlled email address.
  7. Attacker completes the password reset process using the intercepted token.
  8. Attacker logs in to the site as the administrator, achieving full control over the WooCommerce environment.

Impact

Successful exploitation results in full administrative account takeover of the WordPress instance. This allows attackers to exfiltrate customer data, inject malicious scripts, manipulate payment configurations, and potentially deploy persistent backdoors within the WooCommerce environment. The vulnerability affects all users of the FooSales plugin version 1.43.0 and older.

Recommendation

Prioritized actions for detection engineering and security teams:

  • Update the FooSales - Point of Sale (POS) for WooCommerce plugin to the latest version (patch version > 1.43.0) immediately.
  • Audit logs for unauthorized account detail modifications targeting administrative users, specifically monitoring for frequent changes to email addresses.
  • Review WordPress application logs for suspicious activity originating from accounts with FooSales Cashier or similar roles.
  • Disable account registration and tighten user privilege management until the patch is applied.

Immediate actions

Upgrade FooSales plugin to version > 1.43.0

IT Operations 24h

Mitigations

Upgrade FooSales plugin to version > 1.43.0

immediate IT Operations

CVE-2026-77183