WordPress · Wpc Shop As A Customer For Woocommerce · CVE-2026-95687
**Name of the Vulnerable Software and Affected Versions**
WPC Shop as a Customer for WooCommerce versions prior to 2.0.1
**Description**
This issue allows for privilege escalation via account takeover. An authenticated attacker can gain full Administrator-level access to a site by supplying an Administrator's user ID to the 'wpcsa login' endpoint. The plugin fails to properly validate the target user's role before issuing a new authentication session, which enables the attacker to receive a full Administrator session cookie without providing the required password.
**Recommendations**
Update WPC Shop as a Customer for WooCommerce to version 2.0.1 or later.
Restrict access to the 'wpcsa login' endpoint to minimize the risk of exploitation.