PatchSiren cyber security CVE debrief
CVE-2026-14444 Very Good Plugins CVE debrief
The WP Fusion (Pro) plugin for WordPress has a Privilege Escalation vulnerability in all versions up to, and including, 3.47.13. This is due to insufficient authorization checks on the role parameter in the ThriveCart Auto Login handler's thrivecart() function. Authenticated attackers with Subscriber-level access and above, who possess the access_key, can create a new user account with administrator privileges and gain full control over the WordPress site. The required access_key is intentionally shared with ThriveCart customers as part of the plugin's documented setup process.
- Vendor
- Very Good Plugins
- Product
- WP Fusion (Pro)
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-09-07
- Original CVE updated
- 2026-09-07
- Advisory published
- 2026-09-07
- Advisory updated
- 2026-09-07
Who should care
WordPress site administrators and defenders who use the WP Fusion (Pro) plugin and have the ThriveCart Auto Login feature enabled should assess their exposure and take defensive actions.
Why it matters
The WP Fusion (Pro) plugin for WordPress has a Privilege Escalation vulnerability that allows authenticated attackers to create a new user account with administrator privileges. Defenders should prioritize verifying the presence of this vulnerability in their WordPress installations and restrict access to the ThriveCart Auto Login feature.
- Authenticated attackers with Subscriber-level access and above can create a new user account with administrator privileges.
- The required access_key is intentionally shared with ThriveCart customers, making it accessible to attackers who have made a purchase.
- The vulnerability is only exploitable when the ThriveCart Auto Login option is enabled.
- Defenders should verify the presence of this vulnerability in their WordPress installations and restrict access to the ThriveCart Auto Login feature.
Technical summary
The WP Fusion (Pro) plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 3.47.13. This is due to insufficient authorization checks on the role parameter in the ThriveCart Auto Login handler's thrivecart() function. Authenticated attackers with Subscriber-level access and above, who possess the access_key, can create a new user account with administrator privileges and gain full control over the WordPress site. The required access_key is intentionally shared with ThriveCart customers as part of the plugin's documented setup process, making it accessible to attackers who have made a purchase. The vulnerability is only exploitable when the ThriveCart Auto Login option is
Defensive priority
Defenders should prioritize verifying the presence of this vulnerability in their WordPress installations and restrict access to the ThriveCart Auto Login feature.
Recommended defensive actions
- Verify the presence of WP Fusion (Pro) plugin version 3.47.13 or earlier in your WordPress installation.
- Restrict access to the ThriveCart Auto Login feature to prevent exploitation.
- Monitor for suspicious activity related to user account creation and administrator privileges.
- Consider updating to a patched version of the WP Fusion (Pro) plugin if available.
- Review compensating controls for exposed systems while remediation is scheduled and verified.
- Check relevant monitoring, detection, and logs for exposed assets that need extra review.
- Track exceptions, retest remediated assets, and close the item only after evidence is documented.
Evidence notes
The vulnerability is only exploitable when the ThriveCart Auto Login option is enabled. The access_key is intentionally shared with ThriveCart customers, making it accessible to attackers who have made a purchase.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-14444 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-14444
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-14444 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-14444
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://wpfusion.com/documentation/faq/changelog/
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.