PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-14444 Very Good Plugins CVE debrief

The WP Fusion (Pro) plugin for WordPress has a Privilege Escalation vulnerability in all versions up to, and including, 3.47.13. This is due to insufficient authorization checks on the role parameter in the ThriveCart Auto Login handler's thrivecart() function. Authenticated attackers with Subscriber-level access and above, who possess the access_key, can create a new user account with administrator privileges and gain full control over the WordPress site. The required access_key is intentionally shared with ThriveCart customers as part of the plugin's documented setup process.

Vendor
Very Good Plugins
Product
WP Fusion (Pro)
CVSS
HIGH 7.5
CISA KEV
Not listed in stored evidence
Original CVE published
2026-09-07
Original CVE updated
2026-09-07
Advisory published
2026-09-07
Advisory updated
2026-09-07

Who should care

WordPress site administrators and defenders who use the WP Fusion (Pro) plugin and have the ThriveCart Auto Login feature enabled should assess their exposure and take defensive actions.

Why it matters

The WP Fusion (Pro) plugin for WordPress has a Privilege Escalation vulnerability that allows authenticated attackers to create a new user account with administrator privileges. Defenders should prioritize verifying the presence of this vulnerability in their WordPress installations and restrict access to the ThriveCart Auto Login feature.

  • Authenticated attackers with Subscriber-level access and above can create a new user account with administrator privileges.
  • The required access_key is intentionally shared with ThriveCart customers, making it accessible to attackers who have made a purchase.
  • The vulnerability is only exploitable when the ThriveCart Auto Login option is enabled.
  • Defenders should verify the presence of this vulnerability in their WordPress installations and restrict access to the ThriveCart Auto Login feature.

Technical summary

The WP Fusion (Pro) plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.47.13. This is due to insufficient authorization checks on the role parameter in the ThriveCart Auto Login handler's thrivecart() function. Authenticated attackers with Subscriber-level access and above, who possess the access_key, can create a new user account with administrator privileges and gain full control over the WordPress site. The required access_key is intentionally shared with ThriveCart customers as part of the plugin's documented setup process, making it accessible to attackers who have made a purchase. The vulnerability is only exploitable when the ThriveCart Auto Login option is

Defensive priority

Defenders should prioritize verifying the presence of this vulnerability in their WordPress installations and restrict access to the ThriveCart Auto Login feature.

Recommended defensive actions

  • Verify the presence of WP Fusion (Pro) plugin version 3.47.13 or earlier in your WordPress installation.
  • Restrict access to the ThriveCart Auto Login feature to prevent exploitation.
  • Monitor for suspicious activity related to user account creation and administrator privileges.
  • Consider updating to a patched version of the WP Fusion (Pro) plugin if available.
  • Review compensating controls for exposed systems while remediation is scheduled and verified.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.
  • Track exceptions, retest remediated assets, and close the item only after evidence is documented.

Evidence notes

The vulnerability is only exploitable when the ThriveCart Auto Login option is enabled. The access_key is intentionally shared with ThriveCart customers, making it accessible to attackers who have made a purchase.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-14444 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-14444

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-14444 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-14444

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.