<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>WPC Shop as a Customer for WooCommerce (&lt;= 2.0.0) - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/products/wpc-shop-as-a-customer-for-woocommerce--2.0.0/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 01 Oct 2026 10:40:14 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/products/wpc-shop-as-a-customer-for-woocommerce--2.0.0/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Privilege Escalation in WPC Shop as a Customer for WooCommerce</title><link>https://feed.craftedsignal.io/briefs/2026-10-cve-2026-95687/</link><pubDate>Thu, 01 Oct 2026 10:40:14 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-cve-2026-95687/</guid><description>An improper role validation vulnerability in the WPC Shop as a Customer for WooCommerce plugin allows authenticated attackers to perform account takeover and gain administrative access via the wpcsa_login endpoint.</description><content:encoded><![CDATA[<p>The WPC Shop as a Customer for WooCommerce plugin for WordPress is vulnerable to privilege escalation in all versions up to and including 2.0.0. The vulnerability stems from a lack of proper role validation within the wpcsa_login endpoint. An attacker with a standard authenticated account can interact with this endpoint and supply a target administrator's user ID. The plugin subsequently fails to verify the requester's authority, granting the attacker a valid session cookie associated with the target administrator account. This bypasses the need for the administrator's password, effectively resulting in a full administrative account takeover. This flaw is critical for WordPress environments using WooCommerce, as it allows unauthorized users to modify site settings, install malicious plugins, or exfiltrate sensitive customer data.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>Attacker authenticates with a low-privileged account on a target WordPress site.</li>
<li>Attacker enumerates the target administrator user ID (e.g., via author archives or author rest API endpoints).</li>
<li>Attacker crafts an HTTP request targeting the vulnerable /wpcsa_login endpoint.</li>
<li>Attacker includes the target administrator's user ID as a parameter in the request.</li>
<li>The plugin server-side logic processes the request without validating if the current session has the capability to initiate a login as another user.</li>
<li>The server issues a valid session cookie for the administrator account to the attacker.</li>
<li>Attacker updates their browser session with the stolen administrator cookie to gain full site control.</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows an authenticated attacker to gain full WordPress administrative control. This leads to complete site compromise, including the ability to execute arbitrary code via plugin installation, manipulate WooCommerce order data, and potentially access sensitive user information stored within the WordPress database.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Update the WPC Shop as a Customer for WooCommerce plugin to the version containing the patch for CVE-2026-95687 immediately.</li>
<li>If a patch is unavailable, deactivate or remove the WPC Shop as a Customer for WooCommerce plugin from production WordPress environments.</li>
<li>Monitor access logs for repeated or unusual POST requests to the 'wpcsa_login' URI stem, particularly those associated with low-privileged user accounts.</li>
<li>Audit WordPress user accounts to identify unauthorized administrative changes or newly created administrator accounts.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>wordpress</category><category>privilege-escalation</category><category>web-application</category></item></channel></rss>