CVE-2026-75927
Deferred Deferred - Pending Action

Privilege Escalation in PublishPress Capabilities WordPress Plugin

Vulnerability report for CVE-2026-75927, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-09

Last updated on: 2026-09-11

Assigner: Wordfence

Description

The PublishPress Capabilities – User Role Editor, Access Permissions, User Capabilities, Admin Menus plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 2.50.0. This is due to the `addPluginCapabilities()` function unconditionally granting the Editor role all 15 `manage_capabilities_*` capabilities β€” including `manage_capabilities`, `manage_capabilities_roles`, `manage_capabilities_settings`, and `manage_capabilities_backup` β€” via a hard-coded `$eligible_roles = ['administrator', 'editor']` assignment that runs automatically on the first `admin_init` after plugin activation with no administrator opt-in, persisting the grants directly to the database. This makes it possible for authenticated attackers with Editor-level access to elevate their privileges to a site-wide capability manager, enabling them to create, rename, and delete non-system roles, modify capabilities of non-administrator roles, restore role backups, and write arbitrary plugin options whose names begin with `cme_`, `capsman`, `pp_capabilities`, or `presspermit` via `update_option()`. The escalation stops short of full Administrator access, as WordPress's `map_meta_cap` layer still prevents the escalated Editor from granting administrator-only capabilities to other roles; however, all role-management and plugin-settings functionality gated solely on `manage_capabilities_*` capabilities remains fully accessible.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-09
Last Modified
2026-09-11
Generated
2026-09-29
AI Q&A
2026-09-09
EPSS Evaluated
2026-09-27
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
publishpress capabilities to 2.50.0 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-269 The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This WordPress plugin vulnerability allows authenticated users with Editor-level access to escalate their privileges. The plugin automatically grants Editors 15 special capabilities without admin approval, letting them manage roles, modify permissions, and alter plugin settings. This bypasses normal WordPress restrictions.

Detection Guidance

Check WordPress sites for the PublishPress Capabilities plugin versions up to 2.50.0. Look for unauthorized role modifications or new capabilities granted to Editor roles. Review database entries for changes in user roles or capabilities tables.

Impact Analysis

Attackers with Editor access could create admin-level roles, delete existing roles, or change permissions of other users. They could also manipulate plugin settings to potentially install malicious code or take control of the website.

Compliance Impact

This vulnerability allows authenticated attackers with Editor-level access to escalate privileges and modify role capabilities and plugin settings. This could lead to unauthorized access to sensitive data, violating GDPR's data protection requirements and HIPAA's access control mandates.

Mitigation Strategies

Update the PublishPress Capabilities plugin to the latest version. Remove Editor role access to capabilities if not required. Audit user roles and capabilities for unauthorized changes. Consider disabling the plugin temporarily if an update is unavailable.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-75927. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart