OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-94487

HIGH · CVSS 8.1 EPSS 0.13%

Source: NVD + CISA KEV + EPSS · Published 2026-09-23 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

An unauthenticated Cross Site Request Forgery (CSRF) vulnerability exists in PublishPress Capabilities versions 2.50.1 and earlier, allowing attackers to perform unauthorized actions on behalf of users without their consent. This could lead to significant security breaches, including unauthorized content manipulation or privilege escalation. Organizations using affected versions should prioritize patching this vulnerability to safeguard their systems against potential exploitation.

CVE
CVE-2026-94487
Severity
HIGH
CVSS
8.1
EPSS
0.13%

Original NVD Description

Unauthenticated Cross Site Request Forgery (CSRF) in PublishPress Capabilities <= 2.50.1 versions.