CVE-2026-77183: FooSales <= 1.43.0 - Authenticated (Custom+) Privilege Escalation via create_update_customer REST Endpoint
The FooSales – Point of Sale (POS) for WooCommerce plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.43.0. This is due to the plugin not properly validating a user's identity prior to updating their details like email. This makes it possible for authenticated attackers, with FooSales Cashier-level access and above, to change arbitrary user's email addresses, including administrators, and leverage that to reset the user's password and gain access to their account.
Affected Software
Event History
Frequently Asked Questions
Can an unauthenticated attacker exploit this issue?
No. Exploitation requires an authenticated account with FooSales Cashier-level access or higher.
Are administrator accounts within the impact scope?
Yes. An attacker can change the email address of arbitrary users, including administrators, then use password reset functionality to take over those accounts.