{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/foosales--point-of-sale-pos-for-woocommerce--1.43.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:foosales:foosales_point_of_sale_for_woocommerce:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-77183"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["FooSales – Point of Sale (POS) for WooCommerce (\u003c= 1.43.0)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["FooSales"],"content_html":"\u003cp\u003eThe FooSales - Point of Sale (POS) for WooCommerce plugin for WordPress is vulnerable to privilege escalation via an insecure account detail update mechanism present in all versions up to, and including, 1.43.0. The vulnerability stems from the plugin's failure to properly validate a user's identity before allowing updates to sensitive account fields such as the email address. An authenticated attacker possessing at least FooSales Cashier-level access can exploit this flaw to overwrite the email address of any user in the WordPress system, including administrative accounts. By redirecting the email address, the attacker can subsequently trigger a standard WordPress password reset request, receive the reset token, and gain full control over the compromised account. This vulnerability poses a significant risk to e-commerce environments where site integrity and administrative access are critical.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker authenticates to the WordPress site using a low-privilege account with FooSales Cashier permissions.\u003c/li\u003e\n\u003cli\u003eAttacker interacts with the FooSales plugin's account update functionality to modify profile information.\u003c/li\u003e\n\u003cli\u003eAttacker sends a crafted HTTP POST request to the server, targeting the vulnerable user-update endpoint with an arbitrary email address.\u003c/li\u003e\n\u003cli\u003eThe plugin processes the request without sufficient identity validation, successfully updating the target administrator's email to an address controlled by the attacker.\u003c/li\u003e\n\u003cli\u003eAttacker navigates to the WordPress password reset page (wp-login.php?action=lostpassword) and requests a reset for the targeted administrator account.\u003c/li\u003e\n\u003cli\u003eThe WordPress system sends the password reset token to the attacker-controlled email address.\u003c/li\u003e\n\u003cli\u003eAttacker completes the password reset process using the intercepted token.\u003c/li\u003e\n\u003cli\u003eAttacker logs in to the site as the administrator, achieving full control over the WooCommerce environment.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation results in full administrative account takeover of the WordPress instance. This allows attackers to exfiltrate customer data, inject malicious scripts, manipulate payment configurations, and potentially deploy persistent backdoors within the WooCommerce environment. The vulnerability affects all users of the FooSales plugin version 1.43.0 and older.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003ePrioritized actions for detection engineering and security teams:\u003c/p\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the FooSales - Point of Sale (POS) for WooCommerce plugin to the latest version (patch version \u0026gt; 1.43.0) immediately.\u003c/li\u003e\n\u003cli\u003eAudit logs for unauthorized account detail modifications targeting administrative users, specifically monitoring for frequent changes to email addresses.\u003c/li\u003e\n\u003cli\u003eReview WordPress application logs for suspicious activity originating from accounts with FooSales Cashier or similar roles.\u003c/li\u003e\n\u003cli\u003eDisable account registration and tighten user privilege management until the patch is applied.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-10T07:51:21Z","date_published":"2026-10-10T07:51:21Z","id":"https://feed.craftedsignal.io/briefs/2026-10-foosales-privilege-escalation/","summary":"An authentication flaw in FooSales POS for WooCommerce (\u003c= 1.43.0) allows authenticated users with cashier permissions to perform account takeover by modifying arbitrary user email addresses.","title":"Privilege Escalation in FooSales POS for WooCommerce","url":"https://feed.craftedsignal.io/briefs/2026-10-foosales-privilege-escalation/"}],"language":"en","title":"CraftedSignal Threat Feed - FooSales – Point of Sale (POS) for WooCommerce (\u003c= 1.43.0)","version":"https://jsonfeed.org/version/1.1"}