Privilege Escalation Vulnerability in WP Fusion (Pro) Plugin for WordPress
CVE-2026-14444

7.5HIGH

Key Information:

Vendor

WordPress

Vendor
CVE Published:
7 September 2026

What is CVE-2026-14444?

The WP Fusion (Pro) plugin for WordPress is vulnerable to a privilege escalation attack, allowing authenticated users with Subscriber-level access or higher to misuse the ThriveCart Auto Login feature. This vulnerability arises from inadequate authorization checks in the thrivecart() function, enabling attackers with an access_key to create new user accounts with administrator privileges. The access_key, shared with ThriveCart customers during setup, potentially exposes sites to unauthorized control, especially when the ThriveCart Auto Login option is active. Utilizing this vulnerability could lead to a complete takeover of the affected WordPress site.

Affected Version(s)

WP Fusion (Pro) 0 <= 3.47.13

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jarno Vos (jarnovos)
.