Privilege Escalation Vulnerability in WP Fusion (Pro) Plugin for WordPress
CVE-2026-14444
7.5HIGH
What is CVE-2026-14444?
The WP Fusion (Pro) plugin for WordPress is vulnerable to a privilege escalation attack, allowing authenticated users with Subscriber-level access or higher to misuse the ThriveCart Auto Login feature. This vulnerability arises from inadequate authorization checks in the thrivecart() function, enabling attackers with an access_key to create new user accounts with administrator privileges. The access_key, shared with ThriveCart customers during setup, potentially exposes sites to unauthorized control, especially when the ThriveCart Auto Login option is active. Utilizing this vulnerability could lead to a complete takeover of the affected WordPress site.
Affected Version(s)
WP Fusion (Pro) 0 <= 3.47.13