PT-2026-103743 · WordPress · Wpc Shop As A Customer For Woocommerce

·

CVE-2026-95687

·

Published

2026-10-01

·

Updated

2026-10-01

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions WPC Shop as a Customer for WooCommerce versions prior to 2.0.1
Description This issue allows for privilege escalation via account takeover. An authenticated attacker can gain full Administrator-level access to a site by supplying an Administrator's user ID to the 'wpcsa login' endpoint. The plugin fails to properly validate the target user's role before issuing a new authentication session, which enables the attacker to receive a full Administrator session cookie without providing the required password.
Recommendations Update WPC Shop as a Customer for WooCommerce to version 2.0.1 or later. Restrict access to the 'wpcsa login' endpoint to minimize the risk of exploitation.

Fix

LPE

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-95687

Affected Products

Wpc Shop As A Customer For Woocommerce