Impact
A missing authorization check in PublishPress Capabilities allows attackers to manipulate role capabilities, potentially granting themselves elevated privileges. The vulnerability is identified as Missing Authorization (CWE-862). By modifying capability assignments, an attacker can gain unrestricted access to protected functionality within a WordPress site, compromising confidentiality and integrity of the system. The flaw is limited to plugin-specific configuration pages and does not directly impact the core WordPress installation.
Affected Systems
WordPress sites running the PublishPress Capabilities plugin version 2.31.0 or earlier are affected. Any installation of the plugin from the earliest release up to and including 2.31.0 is susceptible.
Risk and Exploitability
The CVSS score of 4.3 indicates a medium severity risk. The EPSS score is less than 1%, suggesting a low probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Likely exploitation requires an authenticated user to access the plugin’s capability management interface, then leverage the unchecked authorization to assign or modify capabilities. No public exploit is documented, and the flaw appears to rely on normal administrative actions within the plugin.
OpenCVE Enrichment