---
id: CVE-2026-95687
title: >-
  The WPC Shop as a Customer for WooCommerce plugin for WordPress is vulnerable
  to privilege escalation via account takeover in all versions up to, and
  including, 2.0.0 This is due to the plugin not properly validating the target
  user's ro…
summary: >-
  The WPC Shop as a Customer for WooCommerce plugin for WordPress is vulnerable
  to privilege escalation via account takeover in all versions up to, and
  including, 2.0.0 This is due to the plugin not properly validating the target
  user's ro…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-269
vendor: wpclever
product: WPC Shop as a Customer for WooCommerce
affected:
  - wpc_shop_as_a_customer_for_woocommerce <= 2.0.0
published: '2026-10-01'
updated: '2026-10-01'
sourceUpdated: '2026-10-01T09:17:10.273'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-95687'
references:
  - url: >-
      https://plugins.trac.wordpress.org/browser/wpc-shop-as-customer/tags/1.3.6/wpc-shop-as-customer.php#L228
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/wpc-shop-as-customer/tags/1.3.6/wpc-shop-as-customer.php#L253
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/browser/wpc-shop-as-customer/tags/1.3.6/wpc-shop-as-customer.php#L96
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/changeset/3708414/wpc-shop-as-customer/trunk/wpc-shop-as-customer.php
    label: security@wordfence.com
  - url: >-
      https://plugins.trac.wordpress.org/changeset?reponame=&new=3708414%40wpc-shop-as-customer%2Ftags%2F2.0.1&old=3708360%40wpc-shop-as-customer%2Ftags%2F2.0.0
    label: security@wordfence.com
  - url: >-
      https://www.wordfence.com/threat-intel/vulnerabilities/id/539cdee3-78bc-42a2-9c34-0f7d46f95d16?source=cve
    label: security@wordfence.com
tags:
  - nvd
  - cve.org
ingestedAt: '2026-10-01T09:41:14.158Z'
---

## Overview

The WPC Shop as a Customer for WooCommerce plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 2.0.0 This is due to the plugin not properly validating the target user's role prior to issuing a new authentication session, allowing an authenticated attacker to log in as any WordPress Administrator by directly supplying an Administrator's user ID to the wpcsa_login endpoint and receiving a full Administrator session cookie without supplying the Administrator's password. This makes it possible for authenticated attackers to perform a direct session takeover, gaining full Administrator-level access to the site.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
