SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-75927

HIGH · CVSS 7.2 EPSS 0.34%

Source: NVD + CISA KEV + EPSS · Published 2026-09-09 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

The PublishPress Capabilities plugin for WordPress is vulnerable to privilege escalation, allowing authenticated users with Editor-level access to gain extensive role management capabilities without administrator consent. This flaw enables them to modify user roles and capabilities, potentially compromising the security and integrity of the site. WordPress site administrators using this plugin should prioritize patching to mitigate the risk of unauthorized privilege escalation.

CVE
CVE-2026-75927
Severity
HIGH
CVSS
7.2
EPSS
0.34%
WordPress

Original NVD Description

The PublishPress Capabilities – User Role Editor, Access Permissions, User Capabilities, Admin Menus plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.50.0. This is due to the `addPluginCapabilities()` function unconditionally granting the Editor role all 15 `manage_capabilities_*` capabilities — including `manage_capabilities`, `manage_capabilities_roles`, `manage_capabilities_settings`, and `manage_capabilities_backup` — via a hard-coded `$eligible_roles = ['administrator', 'editor']` assignment that runs automatically on the first `admin_init` after plugin activation with no administrator opt-in, persisting the grants directly to the database. This makes it possible for authenticated attackers with Editor-level access to elevate their privileges to a site-wide capability manager, enabling them to create, rename, and delete non-system roles, modify capabilities of non-administrator roles, restore role backups, and write arbitrary plugin options whose names begin with `cme_`, `capsman`, `pp_capabilities`, or `presspermit` via `update_option()`. The escalation stops short of full Administrator access, as WordPress's `map_meta_cap` layer still prevents the escalated Editor from granting administrator-only capabilities to other roles; however, all role-management and plugin-settings functionality gated solely on `manage_capabilities_*` capabilities remains fully accessible.