PublishPress Capabilities – User Role Editor, Access Permissions, User Capabilities, Admin Menus: privilege escalation
PublishPress Capabilities – User Role Editor, Access Permissions, User Capabilities, Admin Menus
Privilege escalation in the PublishPress Capabilities – User Role Editor, Access Permissions, User Capabilities, Admin Menus component. Threat level: High (CVSS 7.2).
Who is affected
This vulnerability affects: PublishPress Capabilities – User Role Editor, Access Permissions, User Capabilities, Admin Menus. If you use this component on your site, check the version and update it as soon as possible.
How dangerous
Rating: High, CVSS 7.2 out of 10. It is worth acting before the flaw is exploited.
What this flaw is
Privilege escalation lets a low-privileged user (e.g. a subscriber) raise their level to administrator.
An ordinary, insignificant account becomes one with full power over the site, opening the way to further attacks.
Score breakdown (CVSS vector)
What the CVSS 7.2 rating means in practice:
- The attack can be carried out remotely, over the internet.
- Requires an account with elevated privileges.
- Requires no action from the victim.
- At risk: data confidentiality, integrity (data can be altered), site availability.
Weakness class: CWE-269.
How to fix: privilege escalation
- Update the vulnerable component to the patched version.
- Review all user roles and demote or remove accounts with unexpected privileges.
- Force a password reset and enable two-factor authentication for administrators.
- Restrict who can register and what default role new users receive.
Prefer not to do this yourself? We will handle the update, check for signs of a break-in and secure the site. Write to us →
Does this flaw affect your site?
We will run a free audit: we check versions, plugins, and configuration, and tell you plainly whether you are safe.
Request a free audit →