Sceawere

Vulnerability Detail

CVE-2026-77183UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

FooSales Privilege Escalation Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
8.8
Creation Date
2h ago
Vendor
foosales
Product
FooSales – Point of Sale (POS) for WooCommerce
Attack Type
CWE-269 Improper Privilege Management
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

The FooSales – Point of Sale (POS) for WooCommerce plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.43.0. This is due to the plugin not properly validating a user's identity prior to updating their details like email. This makes it possible for authenticated attackers, with FooSales Cashier-level access and above, to change arbitrary user's email addresses, including administrators, and leverage that to reset the user's password and gain access to their account.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "8.8",
  "pubDate": "2026-10-10T06:16:43.013Z",
  "pubdate": "2026-10-10T06:16:43.013Z",
  "executiveSummary": "The FooSales – Point of Sale (POS) for WooCommerce plugin is susceptible to an account takeover vulnerability that enables unauthorized privilege escalation.\nThe flaw originates from insufficient identity validation during user detail update operations.\nAn authenticated attacker possessing FooSales Cashier-level permissions or higher can exploit this oversight to modify the email addresses of arbitrary users, including site administrators.\nBy altering the email address associated with a target account, an attacker can initiate a standard WordPress password reset request to gain full unauthorized access to the victim's account.\nThis vulnerability carries a critical risk implication, as it facilitates complete site compromise through the takeover of administrative accounts.\nSuccessful exploitation requires the attacker to hold an existing, authenticated, and low-privileged account within the FooSales POS system.\nThis issue affects all versions of the FooSales – Point of Sale (POS) for WooCommerce plugin up to and including 1.43.0.",
  "technicalDetails": "The root cause of this vulnerability is an insecure implementation of the user profile update mechanism within the FooSales – Point of Sale (POS) for WooCommerce plugin. The plugin fails to perform rigorous server-side verification of the current user's authorization status when processing requests to modify sensitive user account attributes, specifically the email address field.\nThe attack vector leverages the lack of integrity checks in the update logic, allowing authenticated users with Cashier-level privileges or higher to inject arbitrary email addresses into the database for any existing user. Because the plugin does not enforce a re-authentication step or perform a privilege check against the target account being modified, the modification request is processed with the authority of the initiating user.\nThe exploitation flow is as follows: 1) The attacker authenticates to the WordPress instance using a valid Cashier-level account. 2) The attacker crafts a request aimed at the user update function of the FooSales plugin, targeting the account details of a higher-privileged user (e.g., an administrator). 3) The malicious request modifies the 'user_email' field of the target account to an email address controlled by the attacker. 4) Once the update is committed to the database, the attacker navigates to the standard WordPress password reset interface (wp-login.php?action=lostpassword). 5) The attacker submits the username or the newly updated email address of the target. 6) The WordPress system sends a password reset link to the email address now controlled by the attacker. 7) The attacker completes the reset process to obtain full administrative access to the site.\nThis vulnerability is particularly severe because it bypasses standard WordPress role-based access controls by manipulating the underlying user authentication identity store. The failure to validate the actor's right to modify the target's email property effectively grants the attacker control over the authentication lifecycle of any user on the system. The impact is absolute: full account takeover, which facilitates data exfiltration, arbitrary code execution via administrative plugin/theme installation, and persistent backend compromise."
}
CVE-2026-77183: FooSales Privilege Escalation Vulnerability (HIGH Severity, CVSS: 8.8) | Sceawere