CVE-2026-80338
Received Received - Intake

Privilege Escalation via AJAX in CMB2 WordPress Plugin

Vulnerability report for CVE-2026-80338, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-24

Last updated on: 2026-09-24

Assigner: WPScan

Description

The CMB2 WordPress plugin before 2.13.0 does not perform any capability check on one of its AJAX actions, allowing users with a role as low as Subscriber to create arbitrary WordPress options and corrupt existing ones, which can break core site settings and take the site offline. Exploitation requires the site's or another CMB2 WordPress plugin before 2.13.0 to have declared an oEmbed field, as the CMB2 WordPress plugin before 2.13.0 registers none of its own. The stored value is never attacker-controlled, so the issue does not lead to privilege escalation.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-24
Last Modified
2026-09-24
Generated
2026-09-24
AI Q&A
2026-09-24
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
cmb2 plugin to 2.13.0 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects the CMB2 WordPress plugin versions before 2.13.0. It allows users with Subscriber-level access or higher to exploit an AJAX action without proper capability checks. This lets attackers create arbitrary WordPress options or corrupt existing ones, potentially breaking core site settings and causing the site to go offline.

Detection Guidance

Check the installed version of the CMB2 WordPress plugin. If it is below 2.13.0, the system is vulnerable. Use commands like 'wp plugin list' in WordPress CLI or inspect the plugin files directly.

Impact Analysis

The impact includes site downtime due to corrupted settings, loss of functionality, and potential disruption of core WordPress features. However, privilege escalation is not possible as stored values are not attacker-controlled.

Compliance Impact

This vulnerability primarily impacts site availability and integrity rather than direct data exposure. By allowing unauthorized users to corrupt WordPress options, it could disrupt core site functions, potentially violating compliance requirements for uptime and data integrity in standards like GDPR or HIPAA. However, the issue does not lead to privilege escalation or direct data theft, which are common compliance concerns.

Mitigation Strategies

Update the CMB2 plugin to version 2.13.0 or later immediately. If updating is not possible, remove the plugin temporarily until an update is available.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-80338. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart