Description
Contributor Privilege Escalation in Frisbii Pay <= 1.8.2 versions.
Published: 2026-06-26
Score: 8.8 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the WordPress Frisbii Pay plugin versions 1.8.2 and earlier, allowing a contributor to gain higher privileges by exploiting a flaw. This is a classic privilege escalation issue (CWE‑862), where unauthorized users can elevate their access level within the WordPress environment. The direct consequence is that an attacker can perform actions normally reserved for administrators, such as changing site settings, adding malicious code, or accessing sensitive information.

Affected Systems

This flaw affects sites that use the Frisbii Pay plugin with versions up to and including 1.8.2. The manufacturer indicates that versions 1.8.2.1 and later contain the fix, so any WordPress site hosting the plugin should verify the installed version.

Risk and Exploitability

The CVSS score of 8.8 ranks this vulnerability as high. is not available, and the case is not listed in the CISA KEV catalog, suggesting a moderate but realistic exploitation probability. The likely attack vector is via the plugin’s web interface accessed by users with contributor privileges; the attacker needs to provide crafted input that the plugin processes without adequate privilege checks. Because this file is part of the WordPress ecosystem, a successful exploitation would grant the attacker control over the site’s administrative functions.

Generated by OpenCVE AI on June 26, 2026 at 17:18 UTC.

Remediation

Vendor Solution

Update the WordPress Frisbii Pay plugin to the latest available version (at least 1.8.2.1).


OpenCVE Recommended Actions

  • Update the Frisbii Pay plugin to version 1.8.2.1 or newer
  • If the plugin is unnecessary, uninstall or disable it to remove the attack surface
  • Ensure WordPress core, themes, and all other plugins are current and limit contributor capabilities to the minimum required for their role

Generated by OpenCVE AI on June 26, 2026 at 17:18 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 26 Jun 2026 18:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 26 Jun 2026 15:15:00 +0000

Type Values Removed Values Added
Description Contributor Privilege Escalation in Frisbii Pay <= 1.8.2 versions.
Title WordPress Frisbii Pay plugin <= 1.8.2 - Privilege Escalation vulnerability
Weaknesses CWE-862
References
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: Patchstack

Published:

Updated: 2026-06-26T17:43:31.563Z

Reserved: 2026-06-18T14:37:40.347Z

Link: CVE-2026-56038

cve-icon Vulnrichment

Updated: 2026-06-26T17:34:03.889Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-26T17:30:05Z

Weaknesses