Executive brief
WP Fusion is a popular WordPress plugin that integrates customer relationship management and marketing automation. The plugin contains a privilege escalation flaw in its ThriveCart auto-login feature that allows attackers with basic subscriber access and knowledge of the shared ThriveCart API key to create administrator accounts and seize complete control of WordPress sites. The vulnerability only affects installations with ThriveCart auto-login enabled.
Technical details
The vulnerability exists in the thrivecart() function's ThriveCart Auto Login handler, which fails to properly validate the role parameter during user account creation. An authenticated attacker with Subscriber-level privileges or higher who possesses the access_key (intentionally shared with ThriveCart customers during setup) can exploit this flaw to create new user accounts with administrator privileges. The attack is network-accessible and does not require additional user interaction beyond having valid subscriber credentials and the publicly documented API key. This is a critical authorization bypass allowing privilege escalation to site administrator. A patch addressing the insufficient authorization checks is required.
Affected products
- WP Fusion WP Fusion up to and including 3.47.13
Timeline
- 2026-09-07: disclosed