<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cpe:2.3:a:wp_fusion:wp_fusion:*:*:*:*:pro:wordpress:*:* - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/cpes/cpe2.3awp_fusionwp_fusionprowordpress/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Mon, 07 Sep 2026 15:33:30 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/cpes/cpe2.3awp_fusionwp_fusionprowordpress/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Privilege Escalation Vulnerability in WP Fusion (Pro) WordPress Plugin</title><link>https://feed.craftedsignal.io/briefs/2026-09-wp-fusion-privesc/</link><pubDate>Mon, 07 Sep 2026 15:33:30 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-wp-fusion-privesc/</guid><description>The WP Fusion (Pro) plugin is vulnerable to unauthorized administrator account creation due to insufficient authorization checks in the ThriveCart Auto Login handler, allowing authenticated users to escalate privileges.</description><content:encoded><![CDATA[<p>The WP Fusion (Pro) plugin for WordPress is vulnerable to a privilege escalation flaw (CVE-2026-14444) affecting all versions up to and including 3.47.13. The vulnerability exists within the ThriveCart Auto Login handler's thrivecart() function, which fails to adequately validate authorization when processing the role parameter.</p>
<p>To exploit this, an attacker must have at least Subscriber-level access on the target WordPress site. The attack requires the attacker to possess the access_key associated with the site's ThriveCart integration, which is typically shared during the plugin's documented setup process. When the ThriveCart Auto Login feature is enabled, an attacker can manipulate the request to create a new user account with administrator privileges. This flaw poses a significant risk to the integrity of affected WordPress installations, as it grants full administrative control to unauthorized parties who have access to the shared integration key.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows an authenticated Subscriber to escalate their privileges to Administrator, resulting in full site compromise. This can lead to total loss of control over the WordPress environment, including unauthorized data access, malicious plugin installation, and potential site-wide persistence.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Upgrade the WP Fusion (Pro) plugin to a version newer than 3.47.13 immediately.</li>
<li>Disable the ThriveCart Auto Login feature if it is not actively required for business operations.</li>
<li>Audit existing administrator accounts to identify any unauthorized users created while the vulnerable version was active.</li>
<li>Rotate the ThriveCart access_key if there is any suspicion of unauthorized access or exposure of the integration credentials.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>wordpress</category><category>privilege-escalation</category><category>web-application</category></item></channel></rss>