{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/wp-easycart--5.9.3/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:wpeasycart:wp_easycart:*:*:*:*:*:wordpress:*:*"],"_cs_cves":[{"cvss":7.2,"id":"CVE-2026-17553"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["WP EasyCart (\u003c= 5.9.3)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["WP EasyCart"],"content_html":"\u003cp\u003eWP EasyCart plugin versions up to and including 5.9.3 contain a critical privilege escalation vulnerability rooted in the ec_ajax_save_page_default_options() AJAX handler. The vulnerability stems from improper input validation where the handler iterates over all provided POST parameters and passes them directly to the update_option() function without an allowlist.\u003c/p\u003e\n\u003cp\u003eAlthough the handler requires either the 'manage_options' capability or the plugin-specific 'wpec_manager' capability, the nonce required to invoke this function is exposed to users holding the 'wpec_store_manager' role. By exploiting this, an authenticated attacker with Store Manager access can modify arbitrary WordPress database options. Attackers can specifically target 'default_role' and 'users_can_register' to force self-registered accounts into the administrator role, resulting in full site compromise.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker authenticates to the target WordPress site with the 'wpec_store_manager' role.\u003c/li\u003e\n\u003cli\u003eAttacker navigates to a frontend product or category template to obtain the required nonce.\u003c/li\u003e\n\u003cli\u003eAttacker crafts an HTTP POST request targeting the ec_ajax_save_page_default_options() handler.\u003c/li\u003e\n\u003cli\u003eAttacker includes 'default_role' set to 'administrator' in the POST data.\u003c/li\u003e\n\u003cli\u003eAttacker includes 'users_can_register' set to '1' in the POST data.\u003c/li\u003e\n\u003cli\u003eThe plugin handler updates the WordPress options table with the malicious values.\u003c/li\u003e\n\u003cli\u003eAttacker triggers the registration process to create a new user account.\u003c/li\u003e\n\u003cli\u003eThe new account is automatically assigned the administrator role upon registration.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an attacker with limited store-management access to escalate privileges to full administrative control over the WordPress instance. This leads to complete site compromise, including the ability to execute arbitrary code, modify content, extract sensitive data, and install backdoors.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cp\u003eUpdate the WP EasyCart plugin to the latest version (v5.9.4 or higher) immediately to patch the vulnerable AJAX handler. If patching is not immediately feasible, restrict access to the dashboard for 'wpec_store_manager' roles or monitor for unusual administrative user registration events.\u003c/p\u003e\n","date_modified":"2026-09-09T05:51:34Z","date_published":"2026-09-09T05:51:34Z","id":"https://feed.craftedsignal.io/briefs/2026-09-wp-easycart-privesc/","summary":"The WP EasyCart plugin up to version 5.9.3 is vulnerable to unauthorized privilege escalation via an insecure AJAX handler, allowing attackers with store manager roles to manipulate site options.","title":"Privilege Escalation in WP EasyCart Plugin","url":"https://feed.craftedsignal.io/briefs/2026-09-wp-easycart-privesc/"}],"language":"en","title":"CraftedSignal Threat Feed - WP EasyCart (\u003c= 5.9.3)","version":"https://jsonfeed.org/version/1.1"}