Description
Incorrect Privilege Assignment vulnerability in miniOrange Custom API for WP custom-api-for-wp allows Privilege Escalation.This issue affects Custom API for WP: from n/a through <= 4.2.2.
Published: 2025-08-20
Score: 9.9 Critical
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an incorrect privilege assignment flaw in the miniOrange Custom API for WP plugin, classified as CWE‑266. It allows an attacker to elevate their privileges and gain high‑level access to the WordPress site, potentially leading to data theft, modification, or arbitrary code execution.

Affected Systems

Any installation of the miniOrange Custom API for WP plugin with a version of 4.2.2 or earlier is affected. This includes all releases ranging from the first available version through to 4.2.2.

Risk and Exploitability

The CVSS score of 9.9 indicates a critical severity, and although the EPSS score is less than 1 %, suggesting a low likelihood of exploitation at this time, the potential impact remains high. The vulnerability is not listed in the CISA KEV catalog, but the absence of active exploitation reports does not diminish the risk. The likely attack vector is remote via the plugin’s exposed API endpoints and requires manipulation of the privilege assignment logic, which may be achievable by an authenticated user with limited rights. Once exploited, the attacker would have unrestricted administrative access to the WordPress backend.

Generated by OpenCVE AI on April 30, 2026 at 08:44 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update the miniOrange Custom API for WP plugin to the latest version (4.2.3 or later) to remove the privilege assignment flaw.
  • Restrict the visibility and accessibility of the plugin’s API endpoints to administrators only, or disable them if not required for your site’s functionality.
  • Review and configure user role permissions to enforce least privilege, ensuring that no user has unnecessary elevated rights that could be abused by this vulnerability.

Generated by OpenCVE AI on April 30, 2026 at 08:44 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-25821 Incorrect Privilege Assignment vulnerability in miniOrange Custom API for WP allows Privilege Escalation. This issue affects Custom API for WP: from n/a through 4.2.2.
History

Thu, 23 Apr 2026 15:00:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Wed, 01 Apr 2026 23:45:00 +0000

Type Values Removed Values Added
Description Incorrect Privilege Assignment vulnerability in miniOrange Custom API for WP allows Privilege Escalation. This issue affects Custom API for WP: from n/a through 4.2.2. Incorrect Privilege Assignment vulnerability in miniOrange Custom API for WP custom-api-for-wp allows Privilege Escalation.This issue affects Custom API for WP: from n/a through <= 4.2.2.
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Tue, 26 Aug 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 21 Aug 2025 12:45:00 +0000

Type Values Removed Values Added
First Time appeared Wordpress
Wordpress wordpress
Vendors & Products Wordpress
Wordpress wordpress

Wed, 20 Aug 2025 08:15:00 +0000

Type Values Removed Values Added
Description Incorrect Privilege Assignment vulnerability in miniOrange Custom API for WP allows Privilege Escalation. This issue affects Custom API for WP: from n/a through 4.2.2.
Title WordPress Custom API for WP <= 4.2.2 - Privilege Escalation Vulnerability
Weaknesses CWE-266
References
Metrics cvssV3_1

{'score': 9.9, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H'}


Subscriptions

Wordpress Wordpress
cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-04-28T16:13:29.775Z

Reserved: 2025-07-16T08:52:07.076Z

Link: CVE-2025-54049

cve-icon Vulnrichment

Updated: 2025-08-20T15:13:32.052Z

cve-icon NVD

Status : Deferred

Published: 2025-08-20T08:15:47.960

Modified: 2026-04-23T15:32:46.290

Link: CVE-2025-54049

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-30T08:45:16Z

Weaknesses