CVE-2026-49058
Deferred Deferred - Pending Action
Unauthenticated Privilege Escalation in LoginPress Pro

Publication date: 2026-06-17

Last updated on: 2026-06-17

Assigner: Patchstack

Description
Unauthenticated Privilege Escalation in LoginPress Pro <= 6.2.2 versions.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-17
Last Modified
2026-06-17
Generated
2026-06-17
AI Q&A
2026-06-17
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 2 associated CPEs
Vendor Product Version / Range
wpbeaverbuilder loginpress_pro to 6.2.2 (inc)
wpbeaver loginpress_pro to 6.2.2 (inc)
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-266 A product incorrectly assigns a privilege to a particular actor, creating an unintended sphere of control for that actor.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

The WordPress LoginPress Pro Plugin, specifically versions 6.2.2 and earlier, contains a high-priority privilege escalation vulnerability identified as CVE-2026-49058.

This flaw allows unauthenticated attackers to escalate their access privileges from low-level to higher levels without needing to log in.

As a result, attackers can potentially gain full control over the affected website.

Impact Analysis

This vulnerability poses a severe risk with a CVSS score of 9.8, indicating it is highly dangerous and likely to be exploited widely.

If exploited, an attacker can gain full control of your website, which can lead to unauthorized changes, data theft, or complete site compromise.

Such control can disrupt your website's availability, integrity, and confidentiality.

Mitigation Strategies

To mitigate the CVE-2026-49058 vulnerability in LoginPress Pro versions 6.2.2 and earlier, you should immediately update the plugin to version 6.2.3 or later.

Until the update is applied, you can apply the mitigation rule provided by Patchstack to block attacks exploiting this privilege escalation flaw.

Compliance Impact

The vulnerability allows unauthenticated attackers to escalate privileges and potentially gain full control of affected websites. This can lead to unauthorized access to sensitive data, which may result in violations of data protection regulations such as GDPR and HIPAA.

Because the flaw falls under OWASP Top 10 category A7 (Identification and Authentication Failures), it indicates a failure in proper authentication controls, which is critical for maintaining compliance with standards that require strict access controls and data protection.

Organizations using affected versions of LoginPress Pro should urgently update to version 6.2.3 or later to mitigate the risk and maintain compliance with relevant security and privacy regulations.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-49058. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart