Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4108 articles · 228290 vulns · 36/41 feeds (7d)
← Back to list
8.8
CVE-2026-95687
wpclever · wpc shop as a customer for woocommerce

WPC Shop as a Customer for WooCommerce <= 2.0.0 - Authenticated (Subscriber+) Privilege Escalation via Missing Role Check on Target User to wpcsa_login AJAX Endpoint

Description

The WPC Shop as a Customer for WooCommerce plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.0.0 This is due to the plugin not properly validating the target user's role prior to issuing a new authentication session, allowing an authenticated attacker to log in as any WordPress Administrator by directly supplying an Administrator's user ID to the wpcsa_login endpoint and receiving a full Administrator session cookie without supplying the Administrator's password. This makes it possible for authenticated attackers to perform a direct session takeover, gaining full Administrator-level access to the site.

Affected Products

VendorProductVersions
wpcleverwpc shop as a customer for woocommerce0

References

  • https://www.wordfence.com/threat-intel/vulnerabilities/id/539cdee3-78bc-42a2-9c34-0f7d46f95d16?source=cve
  • https://plugins.trac.wordpress.org/browser/wpc-shop-as-customer/tags/1.3.6/wpc-shop-as-customer.php#L253
  • https://plugins.trac.wordpress.org/browser/wpc-shop-as-customer/tags/1.3.6/wpc-shop-as-customer.php#L228
  • https://plugins.trac.wordpress.org/browser/wpc-shop-as-customer/tags/1.3.6/wpc-shop-as-customer.php#L96
  • https://plugins.trac.wordpress.org/changeset?reponame=&new=3708414%40wpc-shop-as-customer%2Ftags%2F2.0.1&old=3708360%40wpc-shop-as-customer%2Ftags%2F2.0.0
  • https://plugins.trac.wordpress.org/changeset/3708414/wpc-shop-as-customer/trunk/wpc-shop-as-customer.php

Related News (1 articles)

Tier C
VulDB5d ago
CVE-2026-95687 | wpclever WPC Shop as a Customer Plugin up to 2.0.0 on WordPress wpcsa_login user ID privileges management
→ No new info (linked only)

Discussion (0)

Loading…

CVSS 3.18.8 HIGH
VectorCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA KEV❌ No
Actively exploited❌ No
CWECWE-269
PublishedOct 1, 2026
Last enriched5d ago
Trending Score16
Source articles1
Independent1
Info Completeness5/14
Missing: vendor, product, versions, epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

HIGHCVE-2026-93836EXPKEV
WPC Product Bundles for WooCommerce <= 8.6.6 - Unauthenticated Stored Cross-Site Scripting via 'qty' Parameter
Trending: 105
HIGHCVE-2026-97660
WPC Product Options for WooCommerce <= 4.0.5 - Unauthenticated Stored Cross-Site Scripting via wpcpo-* Array Key via Multipart Field Name
Trending: 16
MEDIUMCVE-2026-104313
WPC Estimated Delivery Date for WooCommerce <= 4.0.1 - Reflected Cross-Site Scripting via 'rule_data' Parameter
Trending: 13
MEDIUMCVE-2026-103888
WPC Smart Quick View for WooCommerce <= 4.4.0 - Reflected Cross-Site Scripting via 'woosq-redirect' Parameter
Trending: 13
MEDIUMCVE-2026-7436
WPC Badge Management for WooCommerce <= 3.1.6 - Authenticated (Contributor+) Stored Cross-Site Scripting via 'text' Attribute

Pin to Dashboard

Verification

State: verified
Confidence: 100%

Vulnerability Timeline

CVE Published
Oct 1, 2026
Discovered by ZDM
Oct 1, 2026