CVE-2026-95687
Received Received - Intake

Privilege Escalation via Account Takeover in WPC Shop for WooCommerce

Vulnerability report for CVE-2026-95687, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-01

Last updated on: 2026-10-01

Assigner: Wordfence

Description

The WPC Shop as a Customer for WooCommerce plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.0.0 This is due to the plugin not properly validating the target user's role prior to issuing a new authentication session, allowing an authenticated attacker to log in as any WordPress Administrator by directly supplying an Administrator's user ID to the wpcsa_login endpoint and receiving a full Administrator session cookie without supplying the Administrator's password. This makes it possible for authenticated attackers to perform a direct session takeover, gaining full Administrator-level access to the site.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-01
Last Modified
2026-10-01
Generated
2026-10-01
AI Q&A
2026-10-01
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
wpc_shop woocommerce_plugin to 2.0.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-269 The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

The WPC Shop as a Customer for WooCommerce plugin for WordPress has a privilege escalation vulnerability due to improper validation of user roles. An authenticated attacker can log in as any WordPress Administrator by supplying an Administrator's user ID to the wpcsa_login endpoint and receiving a full Administrator session cookie without the password. This allows attackers to gain full Administrator-level access to the site.

Detection Guidance

To detect this vulnerability, check WordPress sites running the WPC Shop as a Customer for WooCommerce plugin versions up to 2.0.0. Look for unauthorized Administrator login attempts via the wpcsa_login endpoint or suspicious session cookies tied to Administrator accounts.

Impact Analysis

This vulnerability allows authenticated attackers to take over Administrator accounts, giving them full control over the WordPress site. They can modify content, install malicious plugins, steal data, or disrupt operations. The impact includes unauthorized access, data breaches, and potential site defacement.

Compliance Impact

This vulnerability could lead to non-compliance with GDPR and HIPAA by enabling unauthorized access to sensitive data. GDPR requires protecting personal data, and HIPAA mandates securing protected health information. A breach could result in legal penalties, fines, and reputational damage.

Mitigation Strategies

Update the WPC Shop as a Customer for WooCommerce plugin to the latest version beyond 2.0.0 immediately. If an update is not available, consider disabling or removing the plugin until a patch is released. Review all user accounts for unauthorized Administrator access and revoke any suspicious sessions.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-95687. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart