{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/wpc-shop-as-a-customer-for-woocommerce--2.0.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:wpclever:wpc_shop_as_a_customer_for_woocommerce:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":8.8,"id":"CVE-2026-95687"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["WPC Shop as a Customer for WooCommerce (\u003c= 2.0.0)"],"_cs_severities":["high"],"_cs_tags":["wordpress","privilege-escalation","web-application"],"_cs_type":"advisory","_cs_vendors":["WPClever"],"content_html":"\u003cp\u003eThe WPC Shop as a Customer for WooCommerce plugin for WordPress is vulnerable to privilege escalation in all versions up to and including 2.0.0. The vulnerability stems from a lack of proper role validation within the wpcsa_login endpoint. An attacker with a standard authenticated account can interact with this endpoint and supply a target administrator's user ID. The plugin subsequently fails to verify the requester's authority, granting the attacker a valid session cookie associated with the target administrator account. This bypasses the need for the administrator's password, effectively resulting in a full administrative account takeover. This flaw is critical for WordPress environments using WooCommerce, as it allows unauthorized users to modify site settings, install malicious plugins, or exfiltrate sensitive customer data.\u003c/p\u003e\n\u003ch2 id=\"attack-chain\"\u003eAttack Chain\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eAttacker authenticates with a low-privileged account on a target WordPress site.\u003c/li\u003e\n\u003cli\u003eAttacker enumerates the target administrator user ID (e.g., via author archives or author rest API endpoints).\u003c/li\u003e\n\u003cli\u003eAttacker crafts an HTTP request targeting the vulnerable /wpcsa_login endpoint.\u003c/li\u003e\n\u003cli\u003eAttacker includes the target administrator's user ID as a parameter in the request.\u003c/li\u003e\n\u003cli\u003eThe plugin server-side logic processes the request without validating if the current session has the capability to initiate a login as another user.\u003c/li\u003e\n\u003cli\u003eThe server issues a valid session cookie for the administrator account to the attacker.\u003c/li\u003e\n\u003cli\u003eAttacker updates their browser session with the stolen administrator cookie to gain full site control.\u003c/li\u003e\n\u003c/ol\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows an authenticated attacker to gain full WordPress administrative control. This leads to complete site compromise, including the ability to execute arbitrary code via plugin installation, manipulate WooCommerce order data, and potentially access sensitive user information stored within the WordPress database.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the WPC Shop as a Customer for WooCommerce plugin to the version containing the patch for CVE-2026-95687 immediately.\u003c/li\u003e\n\u003cli\u003eIf a patch is unavailable, deactivate or remove the WPC Shop as a Customer for WooCommerce plugin from production WordPress environments.\u003c/li\u003e\n\u003cli\u003eMonitor access logs for repeated or unusual POST requests to the 'wpcsa_login' URI stem, particularly those associated with low-privileged user accounts.\u003c/li\u003e\n\u003cli\u003eAudit WordPress user accounts to identify unauthorized administrative changes or newly created administrator accounts.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-10-01T10:40:14Z","date_published":"2026-10-01T10:40:14Z","id":"https://feed.craftedsignal.io/briefs/2026-10-cve-2026-95687/","summary":"An improper role validation vulnerability in the WPC Shop as a Customer for WooCommerce plugin allows authenticated attackers to perform account takeover and gain administrative access via the wpcsa_login endpoint.","title":"Privilege Escalation in WPC Shop as a Customer for WooCommerce","url":"https://feed.craftedsignal.io/briefs/2026-10-cve-2026-95687/"}],"language":"en","title":"CraftedSignal Threat Feed - WPC Shop as a Customer for WooCommerce (\u003c= 2.0.0)","version":"https://jsonfeed.org/version/1.1"}