Impact
A vulnerability in PublishPress Capabilities versions up to 2.45.0 allows an attacker with editor role to raise privileges. The flaw is classified under CWE-266 and would enable escalation from a limited editor scope to higher privileges, potentially granting the attacker the ability to modify site content, alter settings, or manage capabilities beyond the intended editor permissions.
Affected Systems
WordPress sites that use the PublishPress Capabilities plugin, with versions 2.45.0 or earlier. The issue is not present in versions 2.50.0 and later.
Risk and Exploitability
The CVSS score of 7.2 indicates a high‑risk condition, although the EPSS score is not available and the issue is not listed in the CISA KEV catalog. The attack vector is inferred to be local via the web interface, requiring the attacker to have an editor‑level account to exploit the privilege escalation. Due to the lack of publicly confirmed exploitation data, the likelihood remains uncertain, but the potential impact justifies immediate remediation.
OpenCVE Enrichment