Description
Editor Privilege Escalation in PublishPress Capabilities <= 2.45.0 versions.
Published: 2026-08-06
Score: 7.2 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability in PublishPress Capabilities versions up to 2.45.0 allows an attacker with editor role to raise privileges. The flaw is classified under CWE-266 and would enable escalation from a limited editor scope to higher privileges, potentially granting the attacker the ability to modify site content, alter settings, or manage capabilities beyond the intended editor permissions.

Affected Systems

WordPress sites that use the PublishPress Capabilities plugin, with versions 2.45.0 or earlier. The issue is not present in versions 2.50.0 and later.

Risk and Exploitability

The CVSS score of 7.2 indicates a high‑risk condition, although the EPSS score is not available and the issue is not listed in the CISA KEV catalog. The attack vector is inferred to be local via the web interface, requiring the attacker to have an editor‑level account to exploit the privilege escalation. Due to the lack of publicly confirmed exploitation data, the likelihood remains uncertain, but the potential impact justifies immediate remediation.

Generated by OpenCVE AI on August 6, 2026 at 15:24 UTC.

Remediation

Vendor Solution

Update the WordPress PublishPress Capabilities plugin to the latest available version (at least 2.50.0).


OpenCVE Recommended Actions

  • Update the PublishPress Capabilities plugin to version 2.50.0 or newer.
  • Apply the principle of least privilege by reducing editor capabilities or removing the editor role where not required.
  • If patching is delayed, restrict editor access to sensitive plugin settings or temporarily disable the vulnerability‑prone functionality until an update can be applied.

Generated by OpenCVE AI on August 6, 2026 at 15:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 06 Aug 2026 14:45:00 +0000

Type Values Removed Values Added
Description Editor Privilege Escalation in PublishPress Capabilities <= 2.45.0 versions.
Title WordPress PublishPress Capabilities plugin <= 2.45.0 - Privilege Escalation vulnerability
Weaknesses CWE-266
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-08-06T14:27:17.244Z

Reserved: 2026-02-25T12:14:47.650Z

Link: CVE-2026-28183

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-06T15:30:04Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment