{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3awp_fusionwp_fusionprowordpress/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:wp_fusion:wp_fusion:*:*:*:*:pro:wordpress:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-14444"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["WP Fusion (Pro) (\u003c= 3.47.13)"],"_cs_severities":["high"],"_cs_tags":["wordpress","privilege-escalation","web-application"],"_cs_type":"advisory","_cs_vendors":["WP Fusion"],"content_html":"\u003cp\u003eThe WP Fusion (Pro) plugin for WordPress is vulnerable to a privilege escalation flaw (CVE-2026-14444) affecting all versions up to and including 3.47.13. The vulnerability exists within the ThriveCart Auto Login handler's thrivecart() function, which fails to adequately validate authorization when processing the role parameter.\u003c/p\u003e\n\u003cp\u003eTo exploit this, an attacker must have at least Subscriber-level access on the target WordPress site. The attack requires the attacker to possess the access_key associated with the site's ThriveCart integration, which is typically shared during the plugin's documented setup process. When the ThriveCart Auto Login feature is enabled, an attacker can manipulate the request to create a new user account with administrator privileges. This flaw poses a significant risk to the integrity of affected WordPress installations, as it grants full administrative control to unauthorized parties who have access to the shared integration key.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an authenticated Subscriber to escalate their privileges to Administrator, resulting in full site compromise. This can lead to total loss of control over the WordPress environment, including unauthorized data access, malicious plugin installation, and potential site-wide persistence.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the WP Fusion (Pro) plugin to a version newer than 3.47.13 immediately.\u003c/li\u003e\n\u003cli\u003eDisable the ThriveCart Auto Login feature if it is not actively required for business operations.\u003c/li\u003e\n\u003cli\u003eAudit existing administrator accounts to identify any unauthorized users created while the vulnerable version was active.\u003c/li\u003e\n\u003cli\u003eRotate the ThriveCart access_key if there is any suspicion of unauthorized access or exposure of the integration credentials.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-09-07T15:33:30Z","date_published":"2026-09-07T15:33:30Z","id":"https://feed.craftedsignal.io/briefs/2026-09-wp-fusion-privesc/","summary":"The WP Fusion (Pro) plugin is vulnerable to unauthorized administrator account creation due to insufficient authorization checks in the ThriveCart Auto Login handler, allowing authenticated users to escalate privileges.","title":"Privilege Escalation Vulnerability in WP Fusion (Pro) WordPress Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-wp-fusion-privesc/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:wp_fusion:wp_fusion:*:*:*:*:pro:wordpress:*:*","version":"https://jsonfeed.org/version/1.1"}